The first part of this research looks at the tricks used by the Kronos banking malware. The malware is being distributed up to now some of the recent samples have been captured about a month ago, dropped from Rig EK. At the beginning of the execution, the malware modifies the Firefox profile, overwriting the. user_pref(“network.spdy.enabled”, false); user_Pref(“app.safebrowsing.enabled””) and “privacy.clearOnShutdown” are supposed to give to the malware more control over the browsers behavior.”]
Source: https://blog.malwarebytes.com/cybercrime/2017/08/inside-kronos-malware/

