Activity dubbed ‘Raspberry Robin’ uses Microsoft Standard Installer and other legitimate processes to communicate with threat actors and execute nefarious commands.
https://threatpost.com/usb-malware-targets-windows-installer/179521/
The misbehaving Firefox add-ons were misusing an API that controls how Firefox connects to the internet.
https://threatpost.com/mozilla-firefox-blocks-malicious-add-ons-installed-by-455k-users/175745/