Over the past few years, cybercriminals have been tricking users to visit malicious websites, but these criminals aren't using some new never-before-seen trick. Instead, they leveraged an unpatched Firefox bug to lure users to the malicious sites, with tech support scams, ad farms, fake gift vouchers, and malware-laced software updates.
If a victim tried to leave the page, the hackers operating the malicious sites triggered an authentication request in a loop. Every time the victim rejected the request, another request is made and a new modal appears. This continues until the victim is forced to close his/her browser altogether or start a new browsing session. This is the result of the firefox bug redirecting to a malicious site with an iframe embedded inside the source code.
The latest report about the bug came from a victim, who reported the issue on Saturday, December 8, 2018. The user reported that upon landing on one of these malicious sites, he was forced to install a suspicious Firefox extension.
The bug remains unfixed for unknown reasons, despite being reported several times, leaving cybercriminals free to abuse it.
Publisher