July 11, 2016 By Larry Loeb 2 min read

Barkly, a computer security firm, had one of its installations sound an alarm due to a new Firefox malware.

It was obvious that a drive-by attempt had been made in an effort to breach the system. A user clicked on a link or visited the wrong site and the malware took advantage — a relatively standard path.

But as SecurityWeek stated, it was the payload of this Firefox malware that was of interest. Even though Barkly prevented the breach, it wasn’t able to distinguish what the attacker was trying to deliver. The malware disguised itself as an update to the Firefox browser that needed a click to activate but otherwise looked normal.

Now for Something Completely Different

Barkly’s analysis of the payload allowed the researchers to finally identify it. The examination revealed that the threat was actually a new variation of the Kovter malware, which made a name for itself by hijacking machines and executing remote, sophisticated campaigns.

“What makes this new variant particularly nasty,” the blog states, “is that it’s the later, fileless version of Kovter, and it’s now using an apparently legitimate certificate. That’s bad news because a legitimate certificate causes plenty of traditional antivirus/endpoint solutions to give the software a pass.”

That use of a legitimate certificate means security products will likely be fooled by the Firefox malware, allowing it to get one step closer to potential victims; it will look like any other Firefox update to the user.

Working Around the Firefox Malware

The good news is that there are ways to work around this malware. For example, if users only update their browsers on demand, any update that appears unrequested should not be installed.

But Firefox also has something called the update channel that automatically delivers upgrades to the user. Many people use this option and, as a result, expect updates to happen without requesting them.

The simplest way to deal with this problem is to turn off automatic updates. Those who want that feature should always verify whether the update is real. Firefox will manually check for updates when requested: If the browser says it is up to date when the user checks, then the upgrade should be discarded.

This method of disguise may become more prevalent for malware as cybercriminals search for new installation techniques. Luckily, simple checks and security measures can defeat it.


UPDATE, 7/13/16, 10:34 a.m. EDT: A Mozilla spokesperson has contacted Security Intelligence with the following statement:

“It is critically important that users keep Firefox up to date to make sure they have the latest security fixes. Automatic updates are the best way to do that. In order to better protect users, Firefox automatically updates itself in the background, so there is no need for users to download updates themselves. We strongly advise that users not disable automatic updates in Firefox.”

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today