Little while ago I was researching how hackers can steal your bitcoin and I came across this chrome extension bitcoinadsremover.
BitcoinWisdom Ads Remover Chrome extension available Chome webstore, flaunts itself as ad removerfrom the BitcoinWisdom.com, a website for consulting all kinds of Bitcoin-related statistics, all presented in easy-to-understand charts.
According to Bitstamp, this extension contains malicious code that is redirecting payments to its own Bitcoin address, instead of the one intended by the user making the transaction. Bitcoin Web app developer Devon Weller confirmed Bitstamp’s findings.
To little my surprise, here hacker became extremely smart.
So let's understand how hacker converts your bitcoin address into his/her favor?
Recently, there were cases of siphoning off bitcoin by changing bitcoin address while pasting at another location. Figure shows how criminals change users’ bitcoin deposit address to steal their money. The flow of carried out attack looks as follows:
An attacker publishes malicious chrome extension in chrome web store. Recently, BitcoinWisdom Ads Remover extension was tampered and loaded with malicious javascript and published to the chrome web store.
A victim downloads and installs add-on from the web store.
A victim performs a transaction to transfer bitcoin to a desired genuine bitcoin address.
Chrome extension, such as BitcoinWisdom Ads Remover replaces the bitcoin address while loading the DOM or while copying the bitcoin address in browser through javascript code. After successful transaction, bitcoin gets deposited into adversary’s account.
A careful analysis gives us information about the author who published the extension into chrome web store and revealed information about social profile of the attacker on Reddit and Github. However, there is a possibility that the author’s account got hacked and malicious person published the tampered version of extension. In this scenario, heterogeneous sources such as malicious chrome extension, bitcoin addresses and social profiles of threat actor correlate together to complete the story of how an attack was carried out.