Back to all lessons
Awareness Lessons
3 months ago

Fake Google Notes Extension Hijacks Crypto Wallet Addresses via Clipboard

The Silent Swap campaign exploits users' tendency to trust familiar-sounding software names, using a fake 'Google Notes' browser extension deployed via unsigned installers to silently hijack clipboard contents and replace legitimate cryptocurrency wallet addresses with attacker-controlled ones. The malware manipulates browser preference files to install itself covertly, bypassing typical extension vetting processes. This attack succeeds largely because users fail to verify the authenticity of software installers and browser extensions before installation. The use of EtherHiding for C2 communication further obscures malicious activity, making detection difficult without robust endpoint and network monitoring. The campaign highlights how a lack of security awareness combined with weak browser configuration controls can result in irreversible financial loss.

Tactical Insight

Immediate actions

  • Only install browser extensions from official, verified sources such as the Chrome Web Store or Firefox Add-ons marketplace, and verify publisher identity before installation.
  • Reject and quarantine any unsigned software installers flagged by endpoint protection tools.
  • Always manually verify cryptocurrency wallet addresses by cross-checking the full address before confirming any transaction, rather than relying solely on clipboard contents.

Long-term improvements

  • Enforce browser extension allowlisting policies via MDM or Group Policy to prevent unauthorized extensions from being installed.
  • Implement application whitelisting to block execution of unsigned or unrecognized installers across all endpoints.
  • Conduct regular security awareness training that specifically covers social engineering tactics like software impersonation and clipboard-hijacking threats.

Detection measures

  • Deploy endpoint detection and response (EDR) solutions capable of monitoring clipboard access events and alerting on anomalous browser preference file modifications.
  • Monitor outbound network traffic for connections to blockchain-based C2 channels (EtherHiding) using threat intelligence feeds and DNS/network-layer inspection.
  • Enable browser extension audit logging and periodically review installed extensions across the enterprise for unauthorized or suspicious entries.