On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

December 4th, 2008

Password stealing malware masquerades as Firefox add-on

Posted by Dancho Danchev @ 7:05 am

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware, Passwords, Spyware and Adware

Tags: Security, Cyberthreats, Firefox, Password Stealing Malware, E-banking, Dancho Danchev

BitDefenderMalware researchers at BitDefender are reporting on a newly discovered malware (Trojan.PWS.ChromeInject.B) that when once dropped in Firefox’s add-ons directory starts operating as such, and attempts to steal accounting data from a predefined list of over a hundred E-banking sites. Once the accounting data is obtained, it’s forwarded to a free web space hosting provider in Russia. Earlier this year, a more severe incident took place when the Vietnamese Language Pack hosted at Mozilla’s official list was infected with malware.

“It drops an executable file (which is a Firefox 3 plugin) and a JavaScript file (detected by Bitdefender as: Trojan.PWS.ChromeInject.A) into the Firefox plugins and chrome folders respectively. It filters the URLs within the Mozilla Firefox browser and whenever encounter the following addresses opened in the Firefox browser it captures the login credentials. It is the first malware that targets Firefox. The filtering is done by a JavaScript file running in Firefox’s chrome environment.”

MalwareDespite the novel approach used, the malware would have made a huge impact if it were released several years ago when E-banking authentication was still in its infancy since plain simple keylogging is one part of the session hijacking tactics used. And while they will indeed obtain the accounting data, this is no longer sufficient for a successful compromise of a bank account. In comparison, the techniques used by sophisticated crimeware like Zeus, Sinowal and Wsnpoem undermine the majority of two-factor authentication mechanisms used by E-banking providers, since once you start doing E-banking from a compromised environment nothing’s really what it seems to be anymore.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 34 Talkback(s)
A minute for you, is an hour for me!
I am a total non-techie who is struggling to learn how to be a responsible computer user. What takes you a minute would probably take me an hour. I don't always have an hour to spare to look things up... (Read the rest)
Posted by: christine yan Posted on: 12/30/08 You are currently: a Guest | | Terms of Use
I am still curious about ISPs.  TripleII | 12/04/08
Folks would lose their Russian porn  Michael Kelly | 12/04/08
No, there is a specific domain.  TripleII | 12/04/08
Net Neutrality  LiquidLearner | 12/04/08
Net Neutrality...  RS9 | 12/05/08
RE: I am still curious about ISPs  bfilipiak@... | 12/05/08
I think there could be concensus.  TripleII | 12/05/08
opendns.com  Dr. John | 12/05/08
Cut them off from the world  Carrion | 12/04/08
All it takes is will, of which there is none.  TripleII | 12/04/08
...  LiquidLearner | 12/04/08
What research?  TripleII | 12/04/08
It's Not a matter of research  Tyr.Anasazi@... | 12/17/08
It's been thought of, it's been done, but ...  terry flores | 12/05/08
Just how does this work?  balaknair | 12/05/08
RE: Password stealing malware masquerades as Firefox add-on  Vquest55@... | 12/05/08
Ditto! [NT]  RS9 | 12/05/08
Not useless  tolique | 12/08/08
WHICH Add-on IS it?...  btljooz | 12/05/08
Carefull!  RS9 | 12/05/08
No add-on  tolique | 12/08/08
risk factor per OS: Windows, Apple, Linux  binstock@... | 12/05/08
Since it's a Firefox add-on...  fairportfan | 12/11/08
RE: Password stealing malware masquerades as Firefox add-on  ksalzman@... | 12/05/08
Do a minute of research!  macawtat | 12/06/08
Re-search  Transdermal | 12/07/08
A minute for you, is an hour for me!  christine yan | 12/30/08
RE: Password stealing malware masquerades as Firefox add-on  donnydo77@... | 12/08/08
Vista IE is malware suscep BFN  donnydo77@... | 12/08/08
RE: Password stealing malware masquerades as Firefox add-on  Sirgwain | 12/10/08
X-Squeeze Me???  QueenMama | 12/11/08
RE: Password stealing malware masquerades as Firefox add-on  w_c_mead | 12/11/08
RE: Password stealing malware masquerades as Firefox add-on  scoobbs@... | 12/14/08
RE: Password stealing malware masquerades as Firefox add-on  Dan_P | 12/15/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline