Threat reportMalwareTL-2026-3088

Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto Recovery Phrases and Private Keys

highACTIVE

Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto (TL-2026-3088), also tracked as Offside Wallet Theft Factory (linked August 2026 campaign), is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Mozilla Firefox (users who installed the malicious add-ons), maps to 8 MITRE ATT&CK techniques (T1036.005, T1056, T1071.001), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-3088

Threat ID
TL-2026-3088
Also known as
Offside Wallet Theft Factory (linked August 2026 campaign)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, cryptocurrency, consumer
Target regions
Global
Detection rules
9
Indicators of compromise
27

How Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto works

16 malicious Firefox extensions (4 Rabby Wallet clones and 12 OKX-style extensions) present fake wallet import screens that capture 12/24-word recovery phrases and 64-character hex private keys and send them to attacker-controlled Cloudflare Workers. Socket linked the campaign with high confidence to an August 2026 campaign (the 'Offside Wallet Theft Factory') through shared code, infrastructure and the tracking marker EQOx7EIPZSNi; Mozilla unpublished the extensions on October 5, 2026.

Socket researchers identified 16 malicious Firefox add-ons impersonating cryptocurrency wallets, split into two implementation groups. The Rabby family (4 extensions, 1,108 identical non-manifest files) clones the Rabby Wallet codebase and adds theft functions directly after the private-key and recovery-phrase import operations. The OKX family (12 extensions, 20 identical non-manifest files) is a small fake OKX-style wallet whose import form accepts only 12- or 24-word phrases and validates the word count before transmitting. The Rabby clones accept a 12-word phrase, a 24-word phrase or a 64-character hex private key (validation in the self._lv function). Users who install an extension and import an existing wallet hand their secrets to the attacker.

Exfiltration uses Cloudflare Workers. The Rabby clones send secrets in a GET request to silent-wind-get.icy-star-f45c.workers.dev with parameters w=<secret>, s=EQOx7EIPZSNi, k=login, a=<import|ui> and t=<timestamp>, which leaves raw secrets in proxy, DNS and URL logs. The OKX handlers use HTTPS POST with a JSON body {a, s, k, w}. One variant has a three-way fallback: navigator.sendBeacon (URL-encoded), fetch POST (mode no-cors, keepalive) and an image-pixel GET. Runtime message types include SEED_PHRASE_IMPORT and WALLET_SYNC. The Rabby clones keep legitimate upstream service URLs (api.rabby.io, static.debank.com), and the manifests declare data_collection_permissions.required = ["none"] while transmitting wallet data. One Worker domain, flat-wildflower-f954.fondationanimalaidrelief.workers.dev, belongs to a variant that is broken because its manifest does not register the background script. A misspelled branding string, 'Raabby WaIIet', is a detection pivot.

Socket attributes the 16 extensions to a single operator because of the identical campaign marker, reused Worker infrastructure (the icy-star-f45c namespace), consistent parameter schema and fixed payload code under varying packaging. The marker EQOx7EIPZSNi also appeared in Socket's August 2026 research on the 'Offside Wallet Theft Factory', a campaign of 77 linked Firefox extension identities (40 confirmed malicious) that impersonated OKX, Rabby and TronLink, used Supabase-controlled remote content switching, Cloudflare Pages phishing pages and a direct C2 IP (77.91.100.175), and modified Rabby's persistAllKeyrings() to leak serialized keyrings. No named threat actor or nation-state attribution is published. Mozilla unpublished the 16 extensions by October 5, 2026, and Socket published its findings on October 7, 2026. Users who already installed them remain exposed. Changing the extension password does not invalidate a stolen recovery phrase or private key, so affected wallets must be treated as permanently compromised and funds moved to a new wallet created on a clean device.

MITRE ATT&CK techniques used in TL-2026-3088

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation

Credential Access

T1056 Input Capture

Command and Control

T1071.001 Web Protocols

Persistence

T1176.001 Browser Extensions

Execution

T1204 User Execution

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.007 Serverless

Affected products and versions in Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto

  • Mozilla — Firefox (users who installed the malicious add-ons)
    Vulnerable versions: Any Firefox version with one of the 16 listed extension IDs installed
    Fixed in: Extensions unpublished by Mozilla on 2026-10-05; installed copies must be removed manually
  • Rabby / OKX (impersonated brands) — Rabby Wallet and OKX Wallet
    Vulnerable versions: Not vulnerable; brands are impersonated by fake extensions

Remediation for Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto

Immediate actions

  • Remove any of the 16 listed Firefox extension IDs from all browser profiles and block those IDs via Firefox enterprise policy (ExtensionSettings)
  • From a clean device, create a new wallet with a new recovery phrase, transfer assets, and revoke token approvals tied to the exposed wallet
  • Treat every account derived from an exposed mnemonic or private key as compromised
  • Block the listed workers.dev hostnames at DNS/proxy and search logs for the query parameter s=EQOx7EIPZSNi (redact field w)
  • Preserve the original XPI files and browser profiles for analysis without running them on analyst workstations

Workarounds

  • Changing the extension password does not invalidate a stolen recovery phrase or private key; rotate the wallet itself

Longer-term hardening

  • Allow-list browser extensions in managed environments and inventory installed extensions regularly
  • Hunt extension inventories for the four background.js hashes and the marker EQOx7EIPZSNi
  • Monitor extension updates that change functionality sharply and combine permission review with code-similarity and infrastructure review
  • Install wallet software only from the vendor's official site or verified store listing

Weaknesses (CWE) in Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto

CWE-200, CWE-506, CWE-522

Timeline of Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto

  • Earliest Mozilla signing records for the linked 'Offside Wallet Theft Factory' extension cluster (Socket, August 2026 research).
  • Latest Mozilla signing records for the linked August 2026 campaign cluster; the shared marker EQOx7EIPZSNi appeared in that research.
  • Public reporting on rogue Firefox extensions hijacking crypto keyrings and clipboard data from the August campaign.
  • Mozilla unpublished the 16 malicious Rabby and OKX clone extensions.
  • Socket published its analysis of the 16 extensions (4 Rabby clones, 12 OKX-style) and linked them with high confidence to the August campaign.
  • Cyber Security News reported the campaign, publishing extension IDs, Worker endpoints and file hashes.

Sources cited for Fake Rabby and OKX Wallet Firefox Extensions Steal Crypto

Detection coverage for TL-2026-3088

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3088 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats