Fake Aggr Chrome Extension Crypto Theft Analysis: Cookie Stealing and Wash Trading
In May 2024, a malicious Chrome extension disguised as an Aggr trading tool was found stealing users' cookies from all websites. The attacker embedded malicious code inside a jQuery file, exfiltrating cookie data to a Russian-language server and using wash trading to steal users' crypto assets. The hacker began plotting 3 years ago, deployed the attack 4 months ago, and leveraged KOLs for promotion.