Malicious Browser Add‑on Targets imToken Users’ Private Keys
ID: c9eae6d3-583d-5a52-96ab-281e77aa4cdd
STIX ID: report--c9eae6d3-583d-5a52-96ab-281e77aa4cdd
Feed Name: GBHackers
Threat Score
Socket’s Threat Research Team uncovered a malicious Chrome extension that impersonates the imToken wallet (extension ID bbhaganppipihlhjgaaeeeefbaoihcgi) and immediately redirects victims to a homoglyph-based phishing site (chroomewedbstorre-detail-extension.com) to harvest seed phrases, private keys, and local passwords via a remote configuration endpoint (jsonkeeper.com/b/KUWNE); IoCs and mitigation steps are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
