A trojan attacks Firefox masquerading as Adobe Flash Player update


Recommended Posts

Trend Micro threat analysts were alerted to the discovery of a spyware (detected as TSPY_EBOD.A) purporting to be an Adobe Flash Player update. Upon execution, the spyware creates a Firefox add-on called ?Adobe Flash Player 0.2,? the installer of which uses JavaScript (detected as JS_EBOD.A) and appears to spread via forum posts.

TSPY_EBOD_A.jpg

The said add-on injects ads into the user?s Google search results pages. More disturbing, however, is its capability to monitor the user?s browsing activities, particularly his/her Google search queries using the Firefox browser. It then sends the information it gathers to http://{BLOCKED}jupdate.com.

We have seen a lot of malware target Internet Explorer in the past. This is probably one of the reasons why a huge number of users are opting to use alternative browsers such as Firefox, Chrome, Safari, and Opera instead. Though this used to be considered a safe computing practice it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser?Firefoxor:rolleyes::rolleyes:

http://blog.trendmicro.com/firefox-addo-sp...search-results/

probably going to get blocked with an update

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

Extensions can be easily installed without prompt. Not through Firefox but through Windows.

Yeah, amazing how secure is FireFox..... :unsure:

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

But that required a user to install something to do that in the first place.

Though this used to be considered a safe computing practice before, it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser?Firefoxb>:rolleyes:s:

Right. Like we're all going to stop using Firefox because of this:rolleyes:s:

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

That is because you read - As the very old saying goes "There is one born every minute". And I make my living cleaning up after they click 2x's without reading what they are clicking on.

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Adobe and Apple too pulled something similar by silently installing the Bonjour service onto PCs via Photoshop. No one should be allowed to do this kind of thing. If companies like MS, Adobe, and Apple want to put themselves on the level of the tech industry's criminals then they have to face the consequences.

Hey, Obama, how about passing a bill to outlaw corporate spyware, instead of more bills for spying on computer users!

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Adobe and Apple too pulled something similar by silently installing the Bonjour service onto PCs via Photoshop. No one should be allowed to do this kind of thing. If companies like MS, Adobe, and Apple want to put themselves on the level of the tech industry's criminals then they have to face the consequences.

Hey, Obama, how about passing a bill to outlaw corporate spyware, instead of more bills for spying on computer users!

The .NET plugin is a plugin, not an addon. It's installed as part of the Framework and Mozilla simply picks it up. Same as installing the Flash player plugin without Firefox. FF will add it automatically upon installation. Firefox is responsible for the security of its own script addons, not Microsoft.

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

When you get off your high horse and stop assuming that a program is secure just because it prompts you on everything, you'll realize that social engineering is exactly how malware spreads these days.

Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Yes, a program exhibiting those characteristics would. Unfortunately, due to your ignorance, you are led by rabidly paranoid hype into believing that the .NET plugin exhibits those characteristics.

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

I think you have a wrong computer software knowledge mate.

The FireFox ADDON/Extension, have NOTHING to do with Microsoft. The problem is in FireFox square.

The .NET plugin is a plugin, not an addon. It's installed as part of the Framework and Mozilla simply picks it up. Same as installing the Flash player plugin without Firefox. FF will add it automatically upon installation.

The .NET plugin provided an uninstallable extension.

Yes, a program exhibiting those characteristics would. Unfortunately, due to your ignorance, you are led by rabidly paranoid hype into believing that the .NET plugin exhibits those characteristics.

Did it install an extension without permission? Check.

Did it introduce a vulnerability? Check.

Did it not provide an uninstaller? Check.

I wouldn't qualify it as malware as that would imply an intention to do harm that I'd hope this didn't, but it still shares those three qualities though.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • BATorrent 3.0.2 by Razvan Serea BATorrent is a lightweight, open-source BitTorrent client built with modern C++ and Qt 6, offering a clean, fast, and privacy-focused alternative to traditional torrent apps. It supports magnet links, .torrent files, resume data, sequential downloading, per-file priorities, and even imports from qBittorrent. Power users benefit from integrated RSS auto-download with regex filtering, duplicate detection, and automatic tracker lists from Stremio. Streaming is seamless thanks to auto-detected players like VLC and IINA. BATorrent includes robust VPN tools—interface binding, auto-detection for WireGuard-based services like Mullvad and NordLynx, kill switch, proxy support, and IP filtering. A full WebUI enables remote control, while integrations with Plex, Jellyfin, and Emby automate library updates. With themes, speed scheduling, system-tray alerts, and cross-platform support for Windows, Linux, and macOS, BATorrent delivers a polished, high-performance torrenting experience. BATorrent features: Core .torrent file and magnet link support Resume data — picks up where you left off after restart Import torrents from qBittorrent Create .torrent files from any file or folder Sequential download mode Per-file priority control (skip, low, normal, high) Seed ratio limits with auto-pause DHT, PEX, UPnP, NAT-PMP RSS Auto-Download Subscribe to RSS feeds — automatically download new torrents as they appear Regex filters — match only what you want (e.g. 1080p|720p, S01E\d+) Per-feed settings — custom save path, check interval (5–1440 min), enable/disable Auto-download — matched items are downloaded automatically in the background Supports magnet links, .torrent URLs, and tags Tray notifications when items are auto-downloaded Duplicate detection — never downloads the same item twice Stremio Stremio Addon System pre-installed — works out of the box Auto tracker list from ngosang/trackerslist Streaming Play while downloading — stream video files before the download is complete Supports mp4, mkv, avi, mov, wmv, flv, webm, m4v, ts Auto-detects installed players (VLC, IINA, system default) VPN & Privacy Interface binding — lock torrent traffic to a specific network interface (e.g. tun0) Auto VPN detection — identifies VPN interfaces (tun, tap, WireGuard, Mullvad, NordLynx, ProtonVPN) Kill switch — automatically pauses all torrents if the VPN interface drops Auto-resume — resumes only the torrents paused by the kill switch when VPN reconnects Proxy support — SOCKS5 and HTTP proxy with optional authentication IP filtering — load P2P blocklists to block unwanted IP ranges Protocol encryption (enabled / forced / disabled) WebUI Remote management — control torrents from any browser at http://localhost:8080 REST API with JSON responses Add torrents via magnet link or .torrent upload Pause, resume, remove torrents remotely View peers and files per torrent Dark theme matching the desktop app HTTP Basic Auth with SHA-256 password hashing Configurable port and remote access (localhost vs 0.0.0.0) Interface 3 themes: Dark, Light, Midnight (bat/vampire aesthetic) Real-time speed graph Detailed panel with tabs: General, Peers, Files, Trackers Filter bar: search by name, filter by state (Active, Downloading, Seeding, Paused, Finished) Drag & drop .torrent files and magnet links Drag & drop reorder in torrent list System tray with notifications (download complete, kill switch events, RSS auto-downloads) Splash screen with bat animation Bilingual: English and Portuguese (BR), auto-detected from system locale Bandwidth Scheduler Alternative speed limits — set different download/upload limits on a schedule Time range — configure active hours (e.g. 01:00 to 07:00), supports overnight ranges Per-day control — choose which days of the week the schedule applies Automatically switches between normal and alternative speeds Media Server Integration Plex — automatically trigger library scan when a download completes Jellyfin / Emby — same automatic library refresh via API Configure server URL and authentication token/key in Settings System Cross-platform: Windows, Linux, macOS Auto-shutdown — automatically shut down PC when all downloads complete (60s cancellable countdown) Auto-update system (AppImage on Linux, installer on Windows, DMG on macOS) CLI arguments: pass .torrent files or magnet: URIs directly Keyboard shortcuts: Space to toggle pause, Ctrl+A to select all, Ctrl+O to open BATorrent 3.0.2 changelog: Phone pairing & WebUI The browser WebUI was reskinned to match the desktop app — same dark palette, Inter font, flat surfaces, the real BATorrent logo (it was a random bat before), and a proper magnet icon. It now looks like the same product, not a separate dashboard. Pairing is one tap and zero typing: the generated WebUI password is now copyable, and the QR code carries the credentials — scanning it from your phone logs straight in (no typing the IP or password), then drops the credentials from the address bar. Search Two new providers: RuTor (CIS sources, no login, via a public TorAPI relay) and Torrents-CSV. Results are sorted by seeders (healthiest first), and each search now times out after 15 s so one dead provider can't hang the UI. Files & trackers Per-file priority is back: right-click a file in the detail panel to set Skip / Low / Normal / High. Rename an individual file inside a torrent (double-click or the file menu), separate from renaming the torrent. Remove a tracker from a torrent (the ✕ on a tracker row); adding was already there. Smart Paste on Ctrl+V — paste a magnet, a 40-char info-hash, or a .torrent URL straight from the clipboard and it's added immediately (text fields still paste text normally). Covers & titles Anime fansub naming ([Group] Title - NN) now resolves to the right show. Audio channel layouts in titles (DDP5.1, 7.1, …) are stripped so they don't pollute cover matching. Under the hood The legacy QWidget interface is gone. QML had been the only UI since 3.0.0 (reachable old code lived behind a hidden --legacy flag); with parity confirmed, the entire QWidget layer — main window, every dialog, the theme manager — was removed (~13,400 lines). The four restored actions above were features that backend already supported but the QML port had never wired. macOS: the WebUI password hash moved out of the keychain into app settings, so launching the app no longer pops a login-keychain password prompt on unsigned builds. The actual password still lives in the keychain. Cleanup: ~400 orphaned translation strings and a batch of dead code removed; internal duplication collapsed; an ARCHITECTURE.md added for contributors. Unit / security / memory tests and the ASan/UBSan/TSan sanitizers stay green. Download: BATorrent 3.0.2 | 30.5 MB (Open Source) Download: BATorrent Portable | 42.3 MB Links: BATorrent Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • How about a global switch to turn the awful things off instead of a registry hack? Then everyone wins.
    • This doesn't strike me as so shocking when... " IT admins do have some control over this rollout. If they choose to opt out, devices in their tenant won't automatically get the dreaded Copilot app"
  • Recent Achievements

    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      468
    2. 2
      PsYcHoKiLLa
      257
    3. 3
      Skyfrog
      79
    4. 4
      ATLien_0
      60
    5. 5
      FloatingFatMan
      60
  • Tell a friend

    Love Neowin? Tell a friend!