A trojan attacks Firefox masquerading as Adobe Flash Player update


Recommended Posts

Trend Micro threat analysts were alerted to the discovery of a spyware (detected as TSPY_EBOD.A) purporting to be an Adobe Flash Player update. Upon execution, the spyware creates a Firefox add-on called ?Adobe Flash Player 0.2,? the installer of which uses JavaScript (detected as JS_EBOD.A) and appears to spread via forum posts.

TSPY_EBOD_A.jpg

The said add-on injects ads into the user?s Google search results pages. More disturbing, however, is its capability to monitor the user?s browsing activities, particularly his/her Google search queries using the Firefox browser. It then sends the information it gathers to http://{BLOCKED}jupdate.com.

We have seen a lot of malware target Internet Explorer in the past. This is probably one of the reasons why a huge number of users are opting to use alternative browsers such as Firefox, Chrome, Safari, and Opera instead. Though this used to be considered a safe computing practice it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser?Firefoxor:rolleyes::rolleyes:

http://blog.trendmicro.com/firefox-addo-sp...search-results/

probably going to get blocked with an update

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

Extensions can be easily installed without prompt. Not through Firefox but through Windows.

Yeah, amazing how secure is FireFox..... :unsure:

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

But that required a user to install something to do that in the first place.

Though this used to be considered a safe computing practice before, it seems it no longer is with the proliferation of malware targetting the most popular alternative Internet browser?Firefoxb>:rolleyes:s:

Right. Like we're all going to stop using Firefox because of this:rolleyes:s:

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

That is because you read - As the very old saying goes "There is one born every minute". And I make my living cleaning up after they click 2x's without reading what they are clicking on.

I edited my comment as it wasn't completely accurate. You can download the .xpi file and unzip it to your profile without the prompt but you will always be notified that a new extension was installed. Just like when MS installed the .net framework extension or whatever the heck it was without the user consenting.

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Adobe and Apple too pulled something similar by silently installing the Bonjour service onto PCs via Photoshop. No one should be allowed to do this kind of thing. If companies like MS, Adobe, and Apple want to put themselves on the level of the tech industry's criminals then they have to face the consequences.

Hey, Obama, how about passing a bill to outlaw corporate spyware, instead of more bills for spying on computer users!

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Adobe and Apple too pulled something similar by silently installing the Bonjour service onto PCs via Photoshop. No one should be allowed to do this kind of thing. If companies like MS, Adobe, and Apple want to put themselves on the level of the tech industry's criminals then they have to face the consequences.

Hey, Obama, how about passing a bill to outlaw corporate spyware, instead of more bills for spying on computer users!

The .NET plugin is a plugin, not an addon. It's installed as part of the Framework and Mozilla simply picks it up. Same as installing the Flash player plugin without Firefox. FF will add it automatically upon installation. Firefox is responsible for the security of its own script addons, not Microsoft.

Seeing as you have to accept it, wait for 5 seconds and then accept to install it AGAIN..

I'll be right back. I'll create a trojan that erases your entire hard drive after you you press "Yes I'm an idiot, I actually pressed run twice on this application, first to download it and then to execute it and now I'm screwed."

When you get off your high horse and stop assuming that a program is secure just because it prompts you on everything, you'll realize that social engineering is exactly how malware spreads these days.

Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

Yes, a program exhibiting those characteristics would. Unfortunately, due to your ignorance, you are led by rabidly paranoid hype into believing that the .NET plugin exhibits those characteristics.

I'm surprised Mozilla didn't complain to MS about this incident. Not only was it installed without permission, not only did it introduce a vulnerability into Firefox, but MS didn't provide an uninstaller! Doesn't that classify as malware?

I think you have a wrong computer software knowledge mate.

The FireFox ADDON/Extension, have NOTHING to do with Microsoft. The problem is in FireFox square.

The .NET plugin is a plugin, not an addon. It's installed as part of the Framework and Mozilla simply picks it up. Same as installing the Flash player plugin without Firefox. FF will add it automatically upon installation.

The .NET plugin provided an uninstallable extension.

Yes, a program exhibiting those characteristics would. Unfortunately, due to your ignorance, you are led by rabidly paranoid hype into believing that the .NET plugin exhibits those characteristics.

Did it install an extension without permission? Check.

Did it introduce a vulnerability? Check.

Did it not provide an uninstaller? Check.

I wouldn't qualify it as malware as that would imply an intention to do harm that I'd hope this didn't, but it still shares those three qualities though.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Final Fantasy VII Remake Part 3 is getting a simultaneous release across PC and all consoles by Pulasthi Ariyasinghe Square Enix showed up to the Summer Game Fest presentation today with multiple trailers showing off its next chapter in the Final Fantasy VII Remake saga. The final chapter of this trilogy now has an official name too, with it being dubbed Final Fantasy VII Revelation, following up Final Fantasy VII Remake and Final Fantasy VII Rebirth from recent years. Vincent Valentine, Cid, Cloud, Barret, Tifa, and more showed up in the trailers as they battle against enemies, or 'Weapons,' from the final chapter. "As the world teeters on the brink of annihilation, the final battle against Sephiroth begins," says the trailer description. "A meteor mars the sky, monstrous planetary guardians wreak havoc across the globe, and the fires of war rage. Now, Cloud and his companions must stand against this chaos to not only decide the planet's fate, but bring a legendary conflict to its conclusion." Following the reveal trailer, the show also dropped some gameplay footage that shows off a new way to travel across the open world using the Highwind airship. Players will be able to swap characters on during battles, use tactical mode to synchronize with allies, and summon their entities. Cid Highwind and Vincent Valentine are joining the party this time too. “FINAL FANTASY VII, first released in 1997, has been beloved by fans for many years and has since become a “legend” in its own right," added producer Yoshinori Kitase. "The FINAL FANTASY VII Remake Series that began in 2020 with everyone’s passionate support is finally reaching its climactic finale with FINAL FANTASY VII REVELATION. The story’s final destination represents my emotions spanning thirty years working on this title" One of the biggest revelations of this announcement, however, was the multiplatform release confirmation from the get-go. Square Enix will be releasing Final Fantasy VII Revelation across PC, Xbox Series X|S, Nintendo Switch 2, and PlayStation 5 in Spring 2027 without any timed exclusivity programs.
    • Hello, Having a simple utility to allow Microsoft's customers to configure the context menu, with a few options like showing the current menu, showing a proposed menu/alternate configurations, loading and saving the settings, and a "reset to default" option would have solved this. Let Microsoft provide a recommended default look-and-feel, maybe a couple alternative configurations, like a basic/simplified version of that, and a more advanced version for that, and that would have been very well-received, I think. Microsoft could even had offered a library of different configurations, similar to what they have done in the past for Windows Media Player skins, Themes, and desktop wallpaper. Regards, Aryeh Goretsky
    • No Steam release. It's gonna fail on PC. Even an Epic Online engineer said that people go there for the free stuff and then immediately go back to Steam.
    • Nice. Admittedly, his other games never interested me, but this seems pretty cool.
    • It's time to say goodbye to Edge and switch back to Firefox. There's no way to disable the ugly rounded corners that appear everywhere. Not even on the page frame. No one uses screens with rounded corners, you idiots.
  • Recent Achievements

    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      482
    2. 2
      PsYcHoKiLLa
      269
    3. 3
      Skyfrog
      78
    4. 4
      Steven P.
      68
    5. 5
      +Edouard
      61
  • Tell a friend

    Love Neowin? Tell a friend!