Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The extension contains several files... webpack_content.js... monitors two input elements for content the user fills into websites... The only file that differs from the rest is webpack_block.js... It also modifies the getter of the password field to steal entered passwords.
It also modifies the getter of the password field to steal entered passwords. Once the request to the API endpoint is sent, the wallet address is extracted from the request, bundled with the password, and sent to the collector as a base64-encoded JSON via MQTT.
The extension contains several files... webpack_content.js... monitors two input elements for content the user fills into websites... The only file that differs from the rest is webpack_block.js... It also modifies the getter of the password field to steal entered passwords.
It also modifies the getter of the password field to steal entered passwords. Once the request to the API endpoint is sent, the wallet address is extracted from the request, bundled with the password, and sent to the collector as a base64-encoded JSON via MQTT.
The gathered data... is then concatenated together into a single string, encoded by base64, and sent to the hardcoded C&C server in the User-Agent HTTP header.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
VenomSoftX is a malicious Chrome browser extension used to steal sensitive information, including cryptocurrency wallet data.
A malicious Chromium-based browser extension installed by ViperSoftX that performs man-in-the-browser attacks against cryptocurrency users. It hooks exchange API requests, swaps recipient wallet addresses, can set transfer amounts to maximum available balances, steals credentials and clipboard data, tampers with displayed crypto addresses, and exfiltrates data via MQTT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.