logo

Crypto Scam "ShieldGuard" Dismantled After Malware Discovery

ID: 11130d51-7065-512e-a41a-b5bc8a05a661

STIX ID: report--11130d51-7065-512e-a41a-b5bc8a05a661

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

...
...

Okta Threat Intelligence uncovered and helped dismantle 'ShieldGuard', a malicious browser extension marketed as a crypto wallet protector that instead harvested wallet addresses and session HTML from Binance, Coinbase, MetaMask and Google services, tracked users, and executed remote code via a command-and-control server; operators showed links to a broader 'Radex' campaign and industry partners removed the extension and disabled its infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.