Drooid Logo
Back to story perspectives

Full Breakdown

GhostPoster Malware Campaign Targets Firefox Users Through Infected Extensions

12/18/2025, 3:45:44 AM

Overview of the GhostPoster Malware Campaign

Koi Security has identified a malicious campaign named GhostPoster, which has infected at least 17 Mozilla Firefox browser extensions. These extensions, advertised as free VPN services, ad blockers, translation tools, and weather forecast applications, have collectively been downloaded over 50,000 times. The malware embedded within these extensions is designed to monitor user activities, disable browser security protections, and enable remote code execution.

Mechanism of Infection

The attack begins when one of the affected extensions is loaded, triggering the retrieval of a PNG logo file. This file contains malicious JavaScript code that extracts a loader, which then connects to external command-and-control (C&C) servers, specifically "www.liveupdt[.]com" or "www.dealctr[.]com," to fetch a multi-stage malware payload. To evade detection, the loader is programmed to fetch the payload only 10% of the time and waits 48 hours between attempts. Additionally, the malware employs time-based delays, activating only after more than six days post-installation.

Capabilities of the Malware

Once activated, GhostPoster can monetize browser activities without user consent through various methods, including:

  • Affiliate Link Hijacking: Intercepting affiliate links to deprive legitimate affiliates of their commissions.
  • Tracking Injection: Inserting Google Analytics tracking codes into every visited webpage to silently profile users.
  • CAPTCHA Bypass: Utilizing multiple methods to bypass CAPTCHA challenges, allowing the malware to evade bot detection.
  • Hidden Iframe Injections: Loading malicious sites from attacker-controlled servers.

List of Infected Extensions

Official Statements & Responses

Koi Security emphasized the severity of the situation, stating, "What they actually deliver is a multi-stage malware payload that monitors everything you browse, strips away your browser's security protections, and opens a backdoor for remote code execution." They also noted that the malware's evasion techniques make it challenging to detect ongoing malicious activities.

Criticism & Opposition

The findings have raised concerns about the reliability of free browser extensions, particularly those promising privacy. Koi Security remarked, "Free VPNs promise privacy, but nothing in life comes free," highlighting the recurring theme of surveillance associated with such services.

What's Next

While the affected extensions have been removed from the Firefox add-ons marketplace, users who have already downloaded them are advised to uninstall the extensions immediately and reset their account passwords. Security experts recommend employing antivirus software and carefully vetting browser extensions to mitigate risks associated with malware campaigns like GhostPoster.