Google Chrome browser discovers malicious extension of VenomSoftX to steal cryptocurrency and sensitive information
CTOnews.com, Nov. 22, Google Chrome browser recently discovered a malicious extension called "VenomSoftX" that can be used to steal users' encrypted currencies and sensitive data. The extension is installed through Windows version of ViperSoftX malware and is a JavaScript-based RAT (remote access Trojan) and cryptocurrency hijackers.
CTOnews.com learned that ViperSoftX malware was exposed as early as 2020 in a joint report released by security research companies Cerberus, Colin Cowie and Fortinet.
Today, security company Avast shares more details about the malicious browser extension and the recent malicious development of the malware. Since the beginning of 2022, Avast has detected and blocked 93000 ViperSoftX infection attempts to its customers, mainly affecting users in the United States, Italy, Brazil and India.
By analyzing the hard-coded wallet addresses in ViperSoftX and VenomSoftX samples, Avast found that by November 8, 2022, both had earned about $130000 for their hackers. The stolen cryptocurrency is obtained by transferring cryptocurrency transactions attempted on the attacked device, excluding profits from parallel activities.