Scareware in Windows delivered by Firefox

20 views
Skip to first unread message

Osdoba, Sascha

unread,
Sep 22, 2025, 8:31:10 AM (4 days ago) Sep 22
to enter...@mozilla.org

Hi,

 

today a user called because he had scare ware on his Windows desktop.

 

 

Firefox was running but you did not see the opened app, I killed Firefox via taskkill, scare ware went away and then we removed the storage folder from his profile. Started Firefox again and scare ware doesn’t came back.

 

URL: https://www.tesaaworld.com/de/news/the-disappearance-of-a-rare-golden-bracelet-from-the-pharaohs-era-inside-the-egyptian-museum-and-investigations-are-ongoing

 

Here is what it looks like and after user clicked “proof that you are not a robot” scare ware was seen on his desktop

 

 

 

I cant reproduce on my device, this robot stuff doesn’t appear here.

 

 

Any ideas to restrict this in any way? I asked for this desktop interactions before but wasn’t quite successful obviously.

 

 

Regards,


Sascha

Osdoba, Sascha

unread,
Sep 24, 2025, 4:34:05 AM (2 days ago) Sep 24
to enter...@mozilla.org

Hi, we found it was send via notifications and so we want to configure these settings now.

 

Thanks to Jonas who guided me (but didn’t replied to the whole list).

 

>I’d venture a guess that this is notifications-based scareware. Thus, Settings, Privacy & Security, Notifications, Settings, remove the site with “allow” permission and cryptic URL (oder wie auch immer Mozilla das ins Deutsche übersetzt hat).

>At least, that’s what is has been the past couple of instances here, the user just accidentally clicked the allow button on the random notifications popup.

 

 

Regards,

 

Sascha

 

Von: enter...@mozilla.org <enter...@mozilla.org> Im Auftrag von Osdoba, Sascha
Gesendet: Montag, 22. September 2025 14:31
An: Enter...@mozilla.org
Betreff: [Mozilla Enterprise] Scareware in Windows delivered by Firefox

 

Hi,

 

today a user called because he had scare ware on his Windows desktop.

 

(image removed)

 

Firefox was running but you did not see the opened app, I killed Firefox via taskkill, scare ware went away and then we removed the storage folder from his profile. Started Firefox again and scare ware doesn’t came back.

 

URL: https://www.tesaaworld.com/de/news/the-disappearance-of-a-rare-golden-bracelet-from-the-pharaohs-era-inside-the-egyptian-museum-and-investigations-are-ongoing

 

Here is what it looks like and after user clicked “proof that you are not a robot” scare ware was seen on his desktop

 

(image removed)

 

 

I cant reproduce on my device, this robot stuff doesn’t appear here.

 

 

Any ideas to restrict this in any way? I asked for this desktop interactions before but wasn’t quite successful obviously.

 

 

Regards,


Sascha

--
You received this message because you are subscribed to the Google Groups "enter...@mozilla.org" group.
To unsubscribe from this group and stop receiving emails from it, send an email to enterprise+...@mozilla.org.
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/enterprise/61359d913cb24be0bec4dee2d54c1cb6%40gsi.de.

Reply all
Reply to author
Forward
0 new messages