Attempt to take control of computer I believe, with fake 'Firefox' security update.

Bug #1734531 reported by J Wilson
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Gufw
Invalid
Undecided
Unassigned
Mozilla Firefox
New
Undecided
Unassigned

Bug Description

The Firewall doesn't seem to be blocking a potential problem for all Internet users. I've had several 'warnings' which have claimed to be from Firefox that have opened a 'new window', which won't close even when you try to do so. As it keeps asking for 'password confirmation' to enable the installation of an "essential security update".

And although I'm no expert that in itself seems suspect to me, and I believe that I've already got Ubuntu set up to automatically update Firefox for me, if it comes directly from them. However this page seems to be using a website address starting with "www.critical.fixes.com/firefox/?clickid=" followed by a long string of numbers and letters, which makes me suspicious, given the way that the 'window behaves.

Indeed a few times after I've tried to stop it in it's track, the genuine Firefox 'pop-up' tells me that a programme is attempting to install software, and asks me if I want to install it. However, even when I respond with 'Don't install', the programme and window doesn't shut down. So the only solution to get rid of it seems to be to 'shut down' manually using the on/off button, however when starting up again next day, Ubuntu asked me to send a 'crash report', but my CURSOR seemed to have been disabled too, so I couldn't click 'send'. It took me two goes of 'switching off and on again to get the CURSOR back again now.

And unless I'm badly mistaken, I believe that this could be an attempt to hack everyone in the world no matter where this 'trick-click' has been hidden. Some people may already have fallen for it and found that their systems are now being held to ransom by this potential 'malware'.

Perhaps I'm wrong, and this is a genuine 'security fix', but I very much doubt it, as the way it popped up out of nowhere was very suspicious to me, as I've said before because it should come through Ubuntu I believe, not from some random 'pop-up window'. I trust you will be able to confirm my suspicions and find a way to block it.

I've already used a 'report window' in Firefox to report it to them, and it seems that Google also gets this too.

Tags: ransomeware
J Wilson (maddad)
information type: Private Security → Public
costales (costales)
Changed in gui-ufw:
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.