Web skimmer loader chain targeting SwapZone/SimpleSwap wallet pages
Detects a multi-stage browser-based web skimming attack. The rule identifies a specific sequence of network activity: a device fetching an obfuscated loader script from 'paste.sh', followed by retrieving payload fragments from the 'Google Sheets Visualization API', and concluding with network interactions with crypto-transaction services 'SwapZone.io' or 'SimpleSwap.io', characteristic of a browser-based wallet-drainer campaign.
Microsoft Sentinel (KQL)

