HomeSecurityPale Moon: Hackers installed malware in older versions

Pale Moon: Hackers installed malware in older versions

Pale MoonThe team behind Pale Moon announced yesterday that its archive server was hacked. Hackers breached the server of the Pale Moon browser project and infected older versions of the browser with malware.

According to the announcement, published by the lead developer, MC Straver, the attack had been going on for 18 months, but was discovered now.

The “archive server” essentially hosts older versions of the browser. The developers want to have older versions available in case any of the users want to abandon the current stable version and revert to an earlier one.

According to Straver, a malicious group had gained access to the archive server (archive.palemoon.org). After gaining access, the hackers ran a malicious script that selectively infected all Pale Moon .exe files stored on the server. To infect the files, the hackers used a variant of Win32/ClipBanker.DY (ESET).

The Pale Moon browser development team was notified of the security the day before yesterday, July 9, and immediately removed the compromised archive server.

Pale Moon: Hackers installed malware in older versions

The attack took place in 2017.
After investigation, it was discovered that the breach had occurred on December 27, 2017 at approximately 3:30 PM.

"It is possible that these dates and times are fake, but considering the backups taken from the archives, it is likely that this is the actual date and time of the breach."

Straver said that all versions prior to Pale Moon 27.6.2 have been infected with the malware. Oddly enough, older versions of the Basilisk web browser were not affected, despite being hosted on the same server.

Unfortunately, the Pale Moon team was unable to detect the breach in May, when the archive server encountered some problems.

They target cryptocurrencies users

Pale Moon developers advise users who have downloaded files from the archive server to scan their systems.

The Win32/ClipBanker.DY trojan infects systems and monitors the operating system's clipboard. This particular variant monitors Bitcoin addresses. Through this, hackers can transfer victims' funds to their own addresses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS