Firefox Zero-Day Used to Install Mac Malware

issued an emergency Firefox patch earlier this week, citing a dangerous zero-day . Because it believed hackers were exploiting the flaw in the wild, Mozilla declined to provide details on the nature of the problem. There are some additional details now, and they suggest the focus of the attack is on cryptocurrency exchange employees.

The vulnerability came as a result of JavaScript flaws that actors could use to produce an exploitable browser crash. That opened the door to running remote code on the system. As second related vulnerability allowed attackers to break out of the Firefox sandbox and into the operating system. Mozilla issued the JavaScript patch on Tuesday and the sandbox fix on Thursday.

Before either of those patches rolled out, Mozilla became aware of an attack leveraging both vulnerabilities. At the time, we only knew the attacks had something to do with Coinbase as the initial bug report came from a researcher who works on both Google’s Project Zero and the Coinbase security team. Now, Coinbase’s head of security Philip Martin says the attack was aimed at Coinbase employees and not users. Martin also notes that other exchanges were in the attacks, although none have stepped forward.

Meanwhile, Apple security expert Patrick Wardle published an analysis of that appears to have installed itself on a fully updated . The hash provided by Wardle matches one from Martin, and the victim of the attack was involved with a cryptocurrency exchange until very recently. Unfortunately, the is novel and avoided Apple’s protection mechanisms, but Wardle believes that Apple will have a patch to change the way macOS scans files downloaded by applications rather than the user.

Wardle also has a copy of the phishing email sent to the victim, who says the attack consisted of a so-called “drive-by download” in Firefox. The website has since vanished, though. The aim was probably to gain access to the crypto wallets used by exchanges to move funds.

The malware samples collected from this attack are only compatible with macOS, but one of the command and control servers has also been known to control Windows malware. It’s possible a Windows version of the attack exists in the wild but has evaded detection thus far.

You might also like More from author

Comments are closed.