{
  "family": "fakeff",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nFakeFF is a specific classification for deceptive malware or Adware that masquerades as a legitimate component of the Mozilla Firefox web browser (or attempts to force the installation of a rogue, trojanized version of the browser). Its primary objective is to trick the user into granting it deep system privileges, allowing it to hijack web traffic, inject advertisements, or facilitate the installation of secondary malware.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nFakeFF is almost exclusively distributed via deceptive web campaigns. Users browsing untrustworthy websites are often confronted with alarming, full-screen pop-ups claiming their \"Firefox browser is out of date\" or a \"critical security patch is required.\" Clicking these links downloads the FakeFF installer instead of a legitimate Mozilla update.\n\nUpon execution, FakeFF leverages its disguise to manipulate the system:\n<ul>\n<li><strong>Deceptive Installation:</strong> The malware installer meticulously copies the icons, branding, and user interface of legitimate Mozilla Firefox software to lull the user into a false sense of security while they click \"Next\" through the wizard.</li>\n<li><strong>Browser Hijacking:</strong> The malware often installs a malicious Browser Helper Object (BHO) or extension into the real browser, or it may entirely replace the Firefox shortcut on the desktop to point to a modified, attacker-controlled executable.</li>\n<li><strong>Traffic Manipulation:</strong> Once integrated, FakeFF intercepts web traffic, forcefully redirecting the user's search queries to dubious affiliate marketing portals, injecting pop-up advertisements into legitimate sites, and silently tracking the user's browsing history.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nWhile FakeFF is primarily an intrusive nuisance designed for ad-fraud, its deceptive nature makes it a significant risk. If an attacker can successfully convince a user to install a fake web browser, they have total control over all unencrypted data entered into that browser, posing a severe risk to passwords and financial information.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Application Removal:</strong> The primary remediation step is to locate and uninstall the fake application. Check the Windows Control Panel for recently installed programs claiming to be \"Firefox Updates\" or bearing suspicious publisher names.</li>\n<li><strong>Shortcut Verification:</strong> Right-click the browser shortcuts on the Desktop and Taskbar. Verify that the \"Target\" field points to the legitimate executable (e.g., `C:\\Program Files\\Mozilla Firefox\\firefox.exe`) and not a malicious script or proxy application.</li>\n<li><strong>Browser Reset and Sweeps:</strong> Perform a complete factory reset of the legitimate web browser to clear any malicious extensions. Run a comprehensive scan with a reputable enterprise anti-malware solution to remove lingering adware components.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Adware.FakeFF",
    "PUP.FakeFirefox",
    "Trojan.FakeBrowser"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1036.005",
    "T1185",
    "T1176"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:35:12Z",
  "type": "Rogue Software / Adware",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}