RomCom’ APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor

Share:

The innocuously named Russian-sponsored cyber threat actor has combined critical and serious vulnerabilities in Windows and Firefox products in a zero-click code execution exploit.

For a brief window of time in October, Russian hackers had the ability to launch arbitrary code against anyone in the world using Firefox or Tor.

On Oct. 8, researchers from ESET first spotted malicious files on a server managed by the Russian advanced persistent threat (APT) RomCom (aka Storm-0978, Tropical Scorpius, UNC2596). The files had gone online just five days earlier, on Oct. 3. Analysis showed that they leveraged two zero-day vulnerabilities: one affecting Mozilla software, the other Windows. The result: an exploit that spread the RomCom backdoor to anyone who visited an infected website, no clicks required.

Luckily, both issues were remediated quickly. “The attackers only had a really small window to try to compromise computers,” explains Romain Dumont, malware researcher with ESET. “Yes, there was a zero-day vulnerability. But, still, it was patched really fast.”

Dark Reading has reached out to Mozilla for comment on this story.

A Zero-Day in Firefox & Tor

The first of the two vulnerabilities, CVE-2024-9680, is a use-after-free opportunity in Firefox animation timelines — the browser mechanism that handles how animations play out based on user interactions with websites. Its power to afford attackers arbitrary command execution earned it a “critical” 9.8 rating from the Common Vulnerability Scoring System (CVSS). 

Nate Nelson

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:25 pm, Jun 27, 2025
weather icon 20°C
L: 19° | H: 22°
clear sky
Humidity: 73 %
Pressure: 1021 mb
Wind: 11 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 6%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:45 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
19° | 22°°C 0 mm 0% 11 mph 84 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
18° | 31°°C 0 mm 0% 7 mph 77 % 1026 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 35°°C 0 mm 0% 9 mph 65 % 1021 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 33°°C 0 mm 0% 10 mph 71 % 1016 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 13 mph 82 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 20°°C 0 mm 0% 10 mph 77 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 19°°C 0 mm 0% 9 mph 84 % 1022 mb 0 mm/h
Tomorrow 7:00 am
weather icon
20° | 20°°C 0 mm 0% 8 mph 83 % 1023 mb 0 mm/h
Tomorrow 10:00 am
weather icon
22° | 22°°C 0 mm 0% 9 mph 74 % 1024 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
27° | 27°°C 0 mm 0% 11 mph 54 % 1024 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
27° | 27°°C 0 mm 0% 11 mph 50 % 1023 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 10 mph 51 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 68 % 1025 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,523.03
-0.21%
Ethereum(ETH)
€2,069.89
-0.08%
Tether(USDT)
€0.85
0.01%
XRP(XRP)
€1.80
-0.36%
Solana(SOL)
€121.90
1.07%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.137133
-0.49%
Shiba Inu(SHIB)
€0.000009
-0.11%
Pepe(PEPE)
€0.000008
-1.89%
Scroll to Top