Executive Summary
In June 2026, cybersecurity researchers identified a malicious campaign named 'Silent Swap,' which targets cryptocurrency users through a fake 'Google Notes' browser extension. Delivered via unsigned .NET and Golang installers, this extension infiltrates Chromium-based browsers by modifying their settings to install itself without user consent. Once active, it monitors the system clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, leading to unauthorized fund transfers. The campaign employs advanced techniques like 'EtherHiding,' utilizing blockchain technology to dynamically update command-and-control servers, enhancing its resilience and evasion capabilities.
This incident underscores a growing trend of sophisticated attacks leveraging trusted platforms and applications to distribute malware. The use of blockchain for command-and-control infrastructure highlights the evolving tactics of threat actors, making detection and mitigation more challenging. Organizations and individuals must remain vigilant, ensuring that browser extensions are sourced from reputable developers and regularly reviewing installed extensions for unauthorized additions.
Why This Matters Now
The 'Silent Swap' campaign exemplifies the increasing sophistication of cyber threats targeting cryptocurrency users. By exploiting trusted platforms and employing advanced evasion techniques, attackers can execute financial theft with minimal detection. This incident serves as a critical reminder for both individuals and organizations to scrutinize browser extensions, maintain updated security protocols, and educate users on the risks associated with unverified software installations.
Attack Path Analysis
The Silent Swap campaign begins with users downloading unsigned installers that deploy a malicious browser extension disguised as 'Google Notes'. This extension gains elevated privileges by modifying browser settings to enable developer mode and bypass security checks. Once installed, it monitors clipboard activity to detect and replace cryptocurrency wallet addresses with those controlled by the attacker. The extension communicates with command-and-control servers using blockchain-based techniques to retrieve updated server details. Finally, the attacker-controlled wallet addresses receive the misdirected cryptocurrency transactions, resulting in financial loss for the victims.
Kill Chain Progression
Initial Compromise
Description
Users download and execute unsigned installers that deploy a malicious browser extension masquerading as 'Google Notes'.
MITRE ATT&CK® Techniques
User Execution: Malicious File
Browser Extensions
Modify Registry
Input Capture: Keylogging
Encrypted Channel: Symmetric Cryptography
Masquerading: Match Legitimate Name or Location
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malicious Software Prevention
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cryptocurrency clipper malware directly targets financial transactions, exploiting wallet addresses and payment systems through browser extensions, creating significant fraud exposure.
Capital Markets/Hedge Fund/Private Equity
Silent Swap infostealer threatens digital asset portfolios and trading operations by manipulating cryptocurrency wallet addresses during high-value institutional transactions.
Computer Software/Engineering
Browser extension vulnerabilities expose software development environments to data exfiltration and lateral movement attacks, compromising source code and development workflows.
Information Technology/IT
IT infrastructure faces zero trust segmentation challenges as clipper malware bypasses traditional security controls through legitimate browser extension distribution channels.
Sources
- Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresseshttps://thehackernews.com/2026/06/silent-swap-crypto-clipper-uses-fake.htmlVerified
- Fake GitHub Stars and AI Videos Mask a Crypto Clipperhttps://www.infosecurity-magazine.com/news/crypto-clipboard-hijacker-fake/Verified
- EthClipper: A Clipboard Meddling Attack on Hardware Wallets with Address Verification Evasionhttps://arxiv.org/abs/2108.14004Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to establish unauthorized connections may be constrained, reducing the likelihood of successful initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may be constrained, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally between workloads may be constrained, reducing the potential blast radius.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command-and-control channels may be constrained, reducing the effectiveness of remote control.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data may be constrained, reducing the risk of financial loss.
The financial impact on victims may be reduced due to constrained attacker capabilities.
Impact at a Glance
Affected Business Functions
- Cryptocurrency Transactions
- Digital Asset Management
- Online Financial Services
Estimated downtime: N/A
Estimated loss: $1,902.45
Potential exposure of cryptocurrency wallet addresses and transaction details.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized modifications to browser settings and prevent malicious extensions from gaining elevated privileges.
- • Utilize Threat Detection & Anomaly Response systems to monitor for unusual clipboard activities and detect unauthorized changes to browser configurations.
- • Enforce Egress Security & Policy Enforcement to control outbound communications and prevent malware from contacting command-and-control servers.
- • Deploy Inline IPS (Suricata) to inspect and block malicious payloads during the initial compromise phase.
- • Educate users on the risks of downloading and executing unsigned installers to reduce the likelihood of initial compromise.



