This article is more than 1 year old
Firefox plug-in Trojan harvests logins
Spy on the wire
Virus writers have latched onto the popularity of Firefox with a new variant on the established practice of stealing online banking passwords.
A password pinching Trojan that poses as a Firefox Plugin is doing the rounds, Romanian security firm BitDefender warns. ChromeInject-A is typically downloaded onto Windows PCs already compromised by other strains of malware.
Once installed, the Trojan sits in Firefox's Plugin folder, activating every time the popular browser is started. The backdoor code looks for data exchanged between a compromised machine and a list of pre-programmed banking sites in Europe, Australia and the US.
Harvested login credentials are captured and subsequently posted to a server located in Russia.
More details on the bank sites targeted, along with the general behaviour of the Trojan, can be found in a write-up by BitDefender here.
BitDefender reports that incidents of the malware are "very low", so the attack is more notable for its novelty than its potency. Malware that capitalises on the popularity of Firefox is rare, but not unprecedented.
Two years ago a spyware package that masqueraded as an extension to the Firefox web browser was spotted on the net. Like ChromeInject-A, FormSpy failed to do much harm. ®