Back to Intelligence

'Raabby WaIIet' Malicious Firefox Extension Campaign: Cryptocurrency Seed Phrase Theft via Cloudflare Workers C2 — OTX Detection Pack

SA
Security Arsenal Team
October 8, 2026
9 min read

A coordinated supply-chain-style campaign has been identified in the Mozilla Firefox Add-ons ecosystem: 16 malicious browser extensions engineered to intercept cryptocurrency wallet credentials during wallet import flows. The operation splits into two clusters:

  • Four large extensions cloning the Rabby Wallet interface — distributed under the homoglyph-obfuscated name "Raabby WaIIet" (capital "I" substituted for lowercase "l") to evade casual inspection and brand-name searches.
  • Twelve smaller extensions impersonating OKX Wallet, plus extensions masquerading as generic wallet portals, desktop utilities, and browser productivity tools.

The attack chain is deliberately low-friction: the victim installs a convincing extension from a legitimate marketplace, initiates a wallet import or unlock, and the extension captures the recovery phrase or private key at the moment of entry. Exfiltration is routed through Cloudflare Workers — serverless endpoints on trusted Cloudflare infrastructure (*.workers.dev) — which defeats reputation-based domain blocking and blends C2 traffic into normal TLS egress. The objective is unambiguous: direct theft of self-custody crypto assets, which are irrecoverable once drained.

This campaign reflects a broader shift in financially motivated threat tradecraft away from endpoint droppers toward browser-native credential interception, where the extension itself is the malware and the browser is the execution environment. Any organization with employees holding corporate or personal crypto assets — treasuries, fintech, Web3 firms, exchanges — should treat this as an active threat.

Threat Actor / Malware Profile

Attribution: Unknown. No named threat actor or malware family has been assigned. The uniformity of the exfiltration pipeline (Cloudflare Workers) and the coordinated, simultaneous publication of 16 extensions strongly suggests a single operator or closely managed affiliate group rather than independent copycats.

Distribution method: Mozilla Firefox Add-ons marketplace abuse. The extensions survive initial review by presenting plausible utility — wallet interfaces, desktop companions, browser tools — and rely on homoglyph brand spoofing ("Raabby WaIIet") to intercept users searching for legitimate wallet software.

Payload behavior: Malicious JavaScript embedded in the extension hooks wallet import/unlock flows. When a user types or pastes a BIP-39 recovery phrase, private key, or keystore password, the content scripts capture the input (via form listeners, input/change event hooks, or DOM scraping) and stage it for exfiltration. The four Rabby clones replicate the legitimate wallet UI closely enough to sustain the deception through a full import workflow.

C2 communication: Stolen material is POSTed to Cloudflare Workers endpoints (*.workers.dev) over HTTPS. This is a deliberate anti-detection choice: Workers domains inherit Cloudflare's reputation, resolve to Cloudflare anycast IPs, and cannot be blocklisted without collateral damage. Detection must therefore key on process-to-domain correlation (browser making unexpected POSTs to workers.dev hosts) rather than domain reputation.

Persistence mechanism: Browser extensions are inherently persistent — they survive reboots, reload with every browser start, and auto-update through the marketplace channel. Removal requires explicit extension uninstallation, not file deletion.

Anti-analysis techniques:

  • Homoglyph naming to evade brand monitoring and user scrutiny
  • Serverless C2 on trusted CDN infrastructure
  • Benign-looking extension metadata and utility descriptions to pass marketplace review
  • Malicious logic confined to in-browser JavaScript, leaving minimal host filesystem artifacts

IOC Analysis

This pulse carries 8 FileHash-SHA256 indicators (21 total across the pulse), representing hashed extension packages (XPI archives) and/or embedded payload components associated with the 16 malicious extensions.

Operationalization guidance for SOC teams:

  1. SHA256 hashes — Push into your EDR/XDR blocklist and threat intel platform immediately. Because browser extensions leave few host artifacts, hash coverage should be extended to Firefox profile directories (%APPDATA%\Mozilla\Firefox\Profiles\*\extensions\*.xpi and the extension-store cache). Sweep these paths across the fleet. Hash sets of this size are also ideal for retro-hunting in file-download telemetry (via DeviceFileEvents in MDE or proxy download logs).
  2. Cloudflare Workers egress — Hunt for POST requests from browser processes to *.workers.dev hosts, correlated with recent extension installs. Not all Workers traffic is malicious, so score by rarity: workers.dev destinations never before seen in your environment, contacted by firefox.exe within a short window of a new extension appearing in the profile.
  3. Extension inventory — Enumerate installed Firefox extensions fleet-wide and flag anything matching *raabby*, *waIIet* (homoglyph variants), or unsolicited OKX-branded add-ons. Legitimate Rabby does not ship as a Firefox extension under that name pattern.

Tooling: Hash verification via Get-FileHash (PowerShell) or shasum -a 256; XPI contents are standard ZIP archives — extract and diff against known-good extension builds. OTX pulses can be ingested directly into MISP, ThreatConnect, or Sentinel TI feeds for automated hash matching.

Detection Engineering

YAML
---
title: Malicious Firefox Extension File Hash Match - Crypto Wallet Stealer Campaign
id: 7f3a1c2e-9b4d-4e6a-a8c1-2d5e7f9a0b11
status: experimental
description: Detects file creation or execution of extension payloads matching SHA256 hashes from the 16-extension Firefox cryptocurrency wallet stealer campaign (Raabby WaIIet / OKX impersonation)
author: Security Arsenal Threat Intelligence
date: 2026/10/08
references:
    - https://socket.dev/blog/firefox-crypto-wallet-stealers
logsource:
    category: file_event
    product: windows
detection:
    selection_hash:
        Hashes|contains:
            - '7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799'
            - 'da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd'
            - 'be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897'
            - 'c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f'
            - 'eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf'
            - '2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51'
            - '225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b'
            - '6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8'
    condition: selection_hash
falsepositives:
    - Unlikely; hashes are campaign-specific
level: critical
tags:
    - attack.credential_access
    - attack.t1555
    - attack.t1552
---
title: Firefox Browser POST to Cloudflare Workers - Potential Crypto Credential Exfiltration
id: 8a4b2d3f-0c5e-5f7b-b9d2-3e6f8a0b1c22
status: experimental
description: Detects Firefox establishing connections to Cloudflare Workers serverless domains, consistent with the exfiltration channel used by the malicious wallet-clone extension campaign
author: Security Arsenal Threat Intelligence
date: 2026/10/08
references:
    - https://socket.dev/blog/firefox-crypto-wallet-stealers
logsource:
    category: network_connection
    product: windows
detection:
    selection_process:
        Image|endswith: '\firefox.exe'
    selection_domain:
        DestinationHostname|endswith: '.workers.dev'
    condition: selection_process and selection_domain
falsepositives:
    - Legitimate extensions and web applications using Cloudflare Workers backends; baseline environment and investigate rare/new destinations
level: high
tags:
    - attack.exfiltration
    - attack.t1041
    - attack.t1102
---
title: Suspicious XPI Extension Installation in Firefox Profile Directory
id: 9b5c3e4a-1d6f-6a8c-c0e3-4f7a9b1c2d33
status: experimental
description: Detects creation of XPI extension files within Firefox profile directories, which may indicate installation of a malicious extension such as the Raabby WaIIet or OKX impersonation add-ons
author: Security Arsenal Threat Intelligence
date: 2026/10/08
references:
    - https://socket.dev/blog/firefox-crypto-wallet-stealers
logsource:
    category: file_event
    product: windows
detection:
    selection_path:
        TargetFilename|contains: '\Mozilla\Firefox\Profiles\'
    selection_ext:
        TargetFilename|endswith: '.xpi'
    condition: selection_path and selection_ext
falsepositives:
    - Legitimate extension installs and updates; correlate with extension name and hash reputation
level: medium
tags:
    - attack.persistence
    - attack.t1176
KQL — Microsoft Sentinel / Defender
// Hunt: Firefox connections to Cloudflare Workers + recent XPI drops in profile dirs
// Campaign: Malicious Firefox crypto wallet stealer extensions (Raabby WaIIet / OKX clones)
let Lookback = 14d;
let MaliciousHashes = dynamic([
    "7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799",
    "da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd",
    "be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897",
    "c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f",
    "eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf",
    "2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51",
    "225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b",
    "6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8"
]);
// 1) Hash hits on extension payloads or dropped files
let HashHits = DeviceFileEvents
    | where TimeGenerated > ago(Lookback)
    | where SHA256 in~ (MaliciousHashes)
    | project HashHitTime=TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName;
// 2) Firefox egress to Cloudflare Workers serverless domains
let WorkersTraffic = DeviceNetworkEvents
    | where TimeGenerated > ago(Lookback)
    | where InitiatingProcessFileName =~ "firefox.exe"
    | where RemoteUrl endswith ".workers.dev"
    | summarize Connections=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated),
        Destinations=make_set(RemoteUrl, 20) by DeviceName, RemoteIP;
// 3) New XPI files written into Firefox profiles (potential malicious extension install)
let XpiDrops = DeviceFileEvents
    | where TimeGenerated > ago(Lookback)
    | where FolderPath has "Mozilla\\Firefox\\Profiles" and FileName endswith ".xpi"
    | project XpiTime=TimeGenerated, DeviceName, FolderPath, FileName, SHA256;
HashHits
| union WorkersTraffic, XpiDrops
| order by DeviceName asc
PowerShell
# IOC Hunt: Malicious Firefox Crypto-Wallet Stealer Extensions
# Checks Firefox profiles for campaign hashes, suspicious extension names, and active Workers C2 connections
$MaliciousHashes = @(
    "7d9d7e80ed52350616be0215a7ded10aaeb9aaa64e34ff8af7f9177c8c855799",
    "da447fe02e4577da97144a4d92b395078954fde1ff196746413837e1e4a20bcd",
    "be246ca5cb1372394e0443df45454f88ca39eb4a8dcfc4a99cb8865100fb4897",
    "c550f0860012e0dfab14ed65a9425961e22025e0ab23fd9d69d294a8aa34db2f",
    "eb134bbf73046800c8177383754cf754b8776ec30cf5cc8a13655d259e49a4bf",
    "2f9270269e631bc4fd634d741afcfc3df8f54e43e40b16f38660fe8ce6c26f51",
    "225f5d6c5d70a7e7f3abf62ea0dda1cf8bf8e70565f7db748b0d8fa602da939b",
    "6b53369fb868efb92b60af40fbd5906fa3d3d8785a7878b4af6e4efd333a4de8"
)
$Findings = @()

# 1) Sweep all Firefox profile extension directories and hash every XPI
$ProfileRoots = Get-ChildItem "$env:APPDATA\Mozilla\Firefox\Profiles" -Directory -ErrorAction SilentlyContinue
foreach ($Profile in $ProfileRoots) {
    $XpiFiles = Get-ChildItem $Profile.FullName -Recurse -Filter "*.xpi" -ErrorAction SilentlyContinue
    foreach ($Xpi in $XpiFiles) {
        $Hash = (Get-FileHash $Xpi.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
        if ($MaliciousHashes -contains ($Hash.ToLower())) {
            $Findings += [PSCustomObject]@{ Type = "HASH MATCH - MALICIOUS EXTENSION"; Path = $Xpi.FullName; SHA256 = $Hash }
        }
        # Flag homoglyph / impersonation naming patterns
        if ($Xpi.Name -match '(?i)raabby|waIIet|0kx|rabby' -and $MaliciousHashes -notcontains ($Hash.ToLower())) {
            $Findings += [PSCustomObject]@{ Type = "SUSPICIOUS EXTENSION NAME"; Path = $Xpi.FullName; SHA256 = $Hash }
        }
    }
    # 2) Parse extensions.json for installed add-on inventory
    $ExtJson = Join-Path $Profile.FullName "extensions.json"
    if (Test-Path $ExtJson) {
        $Exts = (Get-Content $ExtJson -Raw | ConvertFrom-Json).addons
        foreach ($E in $Exts) {
            if ($E.defaultLocale.name -match '(?i)raabby|waIIet|rabby|okx') {
                $Findings += [PSCustomObject]@{ Type = "INSTALLED EXTENSION - WALLET IMPERSONATION"; Path = $E.defaultLocale.name; SHA256 = "n/a" }
            }
        }
    }
}

# 3) Check for active Firefox connections to Cloudflare Workers infrastructure
$WorkersConns = Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
    Where-Object { (Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName -eq "firefox" }
foreach ($Conn in $WorkersConns) {
    try {
        $Ptr = ([System.Net.Dns]::GetHostEntry($Conn.RemoteAddress)).HostName
        if ($Ptr -match 'workers\.dev') {
            $Findings += [PSCustomObject]@{ Type = "FIREFOX -> WORKERS.DEV CONNECTION"; Path = "$($Conn.RemoteAddress):$($Conn.RemotePort)"; SHA256 = $Ptr }
        }
    } catch { }
}

if ($Findings.Count -gt 0) { $Findings | Format-Table -AutoSize } else { Write-Output "[+] No indicators of the malicious Firefox extension campaign found on $env:COMPUTERNAME" }

Response Priorities

Immediate (0-4 hours):

  • Push all 8 SHA256 hashes to EDR blocklists and threat intel platforms; sweep Firefox profile directories (extensions, extension-store, staging caches) fleet-wide for matching files.
  • Alert on any Firefox process egress to previously unseen *.workers.dev destinations; block confirmed campaign Workers endpoints at the proxy (domain-specific, not wildcard, to avoid collateral damage).
  • Inventory installed Firefox extensions via extensions.json and flag Rabby/OKX-branded or homoglyph-named add-ons; force-remove and block reinstallation via Firefox Enterprise Policy (ExtensionSettings).

24 hours:

  • Any user with a confirmed malicious extension install must be treated as credential-compromised: assume recovery phrases and private keys entered during the exposure window are exfiltrated. Immediately migrate affected wallets to newly generated keys on a clean device — rotating passwords alone is insufficient for seed phrase compromise.
  • Review proxy and DNS logs retroactively (30+ days) for Workers.dev POST volume from affected endpoints to scope the exposure window.
  • Audit browser sessions for any corporate SSO or password-manager interaction that occurred while the extension was active; malicious extensions can access all page content, not just wallet flows.

1 week:

  • Implement extension allowlisting via Firefox Enterprise Policies across the organization; disable user-driven add-on installation for roles handling corporate crypto assets.
  • Add *.workers.dev egress from browser processes to standing detection content with rarity-based scoring; extend this to other serverless C2 platforms (Vercel, Netlify Functions, AWS Lambda URLs).
  • Establish a brand-monitoring watch for homoglyph variants of wallet products your organization uses; brief treasury/finance staff on marketplace extension risk and mandate hardware wallets for corporate holdings.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.