GreedyBear is a financially motivated cybercrime threat actor focused on large-scale cryptocurrency theft. The group is associated with campaigns involving more than 150 malicious Firefox browser extensions that were initially benign and later updated to include credential-stealing functionality targeting crypto-wallet users. GreedyBear has also operated fake cryptocurrency investment scams, phishing infrastructure, and malware delivery portals, indicating a broad fraud and theft ecosystem rather than a single delivery mechanism. Reporting links the activity to the earlier Foxy Wallet campaign. High-confidence observed behaviors include initial access through phishing and malicious software distribution, credential theft aimed at cryptocurrency wallets, and post-compromise data exfiltration of stolen wallet credentials. The actor is notable for abusing trusted software distribution channels and combining social engineering with malware-enabled crypto theft at industrial scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GreedyBear is conducting large-scale cybercrime operations involving malicious browser extensions, phishing, and crypto scams to steal credentials and generate illicit revenue.
Industrial-scale crypto theft operation leveraging (1) malicious Firefox extensions impersonating popular crypto wallets and using an 'Extension Hollowing' technique to build trust then inject credential-stealing code, (2) a broad Windows malware distribution pipeline (credential stealers, trojans, and ransomware-like variants) distributed via pirated/repacked software sites, and (3) scam sites posing as crypto products/services. The campaign heavily consolidates infrastructure, with many components resolving to a central server used for C2/credential collection and scam hosting.
Industrial-scale crypto theft operation combining (1) malicious browser extensions impersonating popular crypto wallets, (2) large-scale Windows malware distribution (credential stealers/trojans and some ransomware-like variants), and (3) scam/phishing-style websites posing as crypto products/services. The operation emphasizes infrastructure consolidation (many assets resolving to a single IP) and uses a trust-building/"extension hollowing" workflow to bypass marketplace review and leverage existing positive ratings.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.