Author Topic: Firefox users targeted by rare piece of malware  (Read 4408 times)

0 Members and 1 Guest are viewing this topic.

Offline Frands

  • LzD Friends
  • Hero Member
  • *****
  • Posts: 966
  • Esbjerg, Denmark
    • View Profile
Firefox users targeted by rare piece of malware
« on: December 04, 2008, 06:56:35 PM »
Quote
Researchers at BitDefender have discovered a new type of malicious software that collects passwords for banking sites but targets only Firefox users. The malware, which BitDefender dubbed "Trojan.PWS.ChromeInject.A" sits in Firefox's add-ons folder, said Viorel Canja, the head of BitDefender's lab. The malware runs when Firefox is started.

Please read full article here: http://www.infoworld.com/article/08/12/04/Firefox_users_targeted_by_rare_piece_of_malware_1.html

About Trojan.PWS.ChromeInject.A : http://www.bitdefender.co.uk/NW900-uk--BitDefender-detects-novel-approach-to-stealing-web-passwords.html
Our greatest glory is not in never falling but in rising every time we fall.
- Confucius
-----
Trend Micro Internet Security


Home Forums: http://www.spywarefri.dk/forum
http://securitygarden.blogspot.dk/
https://www.classicrockforums.com/

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 18330
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Firefox users targeted by rare piece of malware
« Reply #1 on: December 04, 2008, 10:02:08 PM »
Thanks for the heads up. 

Recommendations: 


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 912
  • advanced techno feeb
    • View Profile
FireFox users targeted by new trojan
« Reply #2 on: December 05, 2008, 02:22:31 AM »
http://www.pcworld.com/article/154931/.html?tk=rss_news

This could be a bad one...gathers banking information.

Here's a discussion topic about it at DSLReports Mozilla forum:
http://www.dslreports.com/forum/r21525320-Password-Trojan-Poses-as-Firefox-Plugin

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 912
  • advanced techno feeb
    • View Profile
Re: FireFox users targeted by new trojan
« Reply #3 on: December 05, 2008, 02:34:00 AM »
according to CNET:

http://news.cnet.com/Trojan-piggybacks-on-Firefox/2100-7349_3-6098615.html

Quote
A new Trojan horse making the rounds has been installing itself as a Firefox extension, according to security company McAfee.

The FormSpy Trojan attacks computers that have already been infected with the Downloader-AXM Trojan, according to a security advisory McAfee issued Tuesday. Once FormSpy is executed, it installs itself as a component of the Firefox Web browser.

The FormSpy spyware then gleans sensitive information, such as credit card and bank account numbers, from the user's browser and forwards it to a malicious Web site. But this Trojan is capable of other tricks, as well, McAfee noted.

According to one source, the virus is being circulated in a email attachment that can appear as billing info from Wal-mart, and also is marketed as the Numberlinks 0.9 extension for Firefox, taking its name from a legitimate add-on designed to make it easier for Firefox users browse the Web without a mouse.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 18330
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: FireFox users targeted by new trojan
« Reply #4 on: December 05, 2008, 09:51:38 AM »
(Topics Merged.)

This is indeed one nasty malicious script.  Because it can be a drive-by download (downloaded without any interaction by the user), until the vulnerability has been addressed, consider using Internet Explorer for all online credit card purchases and banking activities.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline pastywhitegurl

  • Hero Member
  • *****
  • Posts: 912
  • advanced techno feeb
    • View Profile
Re: Firefox users targeted by rare piece of malware
« Reply #5 on: December 10, 2008, 11:57:50 AM »
How can we know when it's addressed? Will something be posted about it here on Lzd?

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 18330
  • "Stronger than the past, united in our goal."
    • View Profile
    • Security Garden
Re: Firefox users targeted by rare piece of malware
« Reply #6 on: December 10, 2008, 10:04:30 PM »
Because the infected "add-on" is neither supported nor provided by Mozilla, but rather is targeting Mozilla, it will be left to the antivirus vendors to ensure that this password stealing trojan is being detected by them. 

See the following blog posts for additional information:

http://blog.mozilla.com/security/2008/12/08/malicious-firefox-plugin/
http://blog.johnath.com/2008/12/08/firefox-malware/


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.