Mozilla suspends Firefox Send service following malware abuse

(Image credit: Mozilla)

Mozilla has temporarily suspended its file-sharing service Firefox Send following reports that it was abused by cybercriminals who used the service to distribute malware.

The Firefox maker took down the platform after media outlets reached out to inquire about malware-hosting issues that had been found.

While Firefox Send was initially created back in 2017 as one of Mozilla's Test Pilot experiments, the company officially launched the service in March of last year. Firefox Send provides users of Mozilla's browser with the ability to host and share files securely and privately.

All of the files that are uploaded and shared through the service are stored using end-to-end encryption and users can configure how long a file is saved as well as how many times it can be downloaded before it expires.

Distributing malware

Since its launch last year, Firefox Send has seen increased adoption by the malware community whose members use the service to upload malware payloads. Once the malware has been uploaded, hackers share links to it inside emails that are sent out to their targets.

Over the past few months, Firefox Send has been used by cybercriminals to store payloads for a number of different operations including ransomware attacks, financial crime, banking trojans and spyware. Fin7, Sodinokibi and Zloader are just a few of the malware gangs and strains that have used the service to host their payloads. The reason the service has become so popular among cybercriminals is because organizations natively trust Firefox URLs and that it sends encrypted data which makes it harder for malware detection solutions to identify.

For the past few months, security experts have complained about the fact that Firefox Send lacks a “report Abuse” mechanism or a “Report File” button as this would allow them to report malware operations that have abused the platform.

A spokesperson for Mozilla explained to ZDNet that the company will take Firefox Send offline while it improves the product, saying:

"These reports are deeply concerning on multiple levels, and our organization is taking action to address them. We will temporarily take Firefox Send offline while we make improvements to the product. Before relaunching, we will be adding an abuse reporting mechanism to augment the existing Feedback form, and we will require all users wishing to share content using Firefox Send to sign in with a Firefox Account. We are carefully monitoring these developments and looking critically at any additional next steps."

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
The Witcher 4
You're probably not playing The Witcher 4 until 2027 at the earliest, per CD Projekt's latest financial update
DeepSeek
DeepSeek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Two Android phones on a green and blue background showing Google Messages
Google Messages just added a fun upgrade to one of its best chat features
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year