New GhostPoster Attack Leverages PNG Icon to Infect 50,000 Firefox Users
ID: 3de05be5-0e64-5cb9-9974-b238d5e559db
STIX ID: report--3de05be5-0e64-5cb9-9974-b238d5e559db
Feed Name: cybersecurityNews.com
GhostPoster is a widespread malware campaign that leverages malicious Firefox extensions to embed and execute hidden JavaScript payloads inside PNG icon files, evading standard scanners. The threat uses a custom decode/decrypt routine (case/digit swap, Base64, XOR by runtime ID), communicates with C2 infrastructure (e.g., liveupdt.com), disables Content-Security-Policy protections, and conducts traffic hijacking and affiliate fraud, with an estimated ~50,000 affected users and at least 17 compromised extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
