RomCom Backdoor Attacks Use Zero-Day Exploits in Mozilla and Windows (CVE-2024-9680 & CVE-2024-49039

Share:
Aspect Details
Threat Actors RomCom, suspected ties to Russia, also known as Tropical Scorpius, Storm-0978, or UNC2596.
Campaign Overview Exploited zero-day vulnerabilities (CVE-2024-9680 & CVE-2024-49039) to deploy RomCom backdoor via zero-click exploits.
Target Regions (Or Victims) Primarily Europe and North America, with up to 250 affected targets between October 10 – November 4, 2024.
Methodology Fake domains, zero-click exploits, privilege escalation, and stealthy redirection via malicious websites.
Product Targeted Mozilla Firefox, Thunderbird, Tor browsers, and Microsoft Windows Task Scheduler.
Malware Reference RomCom backdoor
Tools Used Fake domains (e.g., redircorrectiv[.]com), Reflective DLL Injection, C2 servers like journalctd[.]live.
Vulnerabilities Exploited CVE-2024-9680 (Use-After-Free in Firefox), CVE-2024-49039 (Elevation of Privilege in Windows Task Scheduler).
TTPs Phishing domains, zero-click exploit chain, DLL injection, and system compromise via backdoor.
Attribution RomCom threat group, suspected Russian ties.
Recommendations Monitor for IOCs, use SOCRadar’s Vulnerability Intelligence to track CVEs, and implement Brand Protection for domain detection.
Source SOCRadar

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:14 pm, Apr 22, 2025
weather icon 16°C
L: 15° | H: 17°
broken clouds
Humidity: 51 %
Pressure: 1017 mb
Wind: 9 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:49 am
Sunset: 8:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 17°°C 0 mm 0% 11 mph 76 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 11°°C 1 mm 100% 12 mph 94 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
8° | 16°°C 0.71 mm 71% 5 mph 91 % 1023 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
8° | 17°°C 0.2 mm 20% 7 mph 90 % 1023 mb 0 mm/h
Sat Apr 26 10:00 pm
weather icon
11° | 18°°C 1 mm 100% 7 mph 98 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 48 % 1017 mb 0 mm/h
Today 7:00 pm
weather icon
14° | 14°°C 0 mm 0% 11 mph 55 % 1016 mb 0 mm/h
Today 10:00 pm
weather icon
10° | 10°°C 0 mm 0% 7 mph 76 % 1016 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 77 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
9° | 9°°C 1 mm 100% 10 mph 94 % 1012 mb 0 mm/h
Tomorrow 7:00 am
weather icon
8° | 8°°C 1 mm 100% 11 mph 93 % 1011 mb 0 mm/h
Tomorrow 10:00 am
weather icon
8° | 8°°C 1 mm 100% 9 mph 93 % 1012 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
9° | 9°°C 1 mm 100% 9 mph 85 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€77,114.70
1.66%
Ethereum(ETH)
€1,419.06
0.16%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.83
-0.97%
Solana(SOL)
€122.12
0.87%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.142906
1.49%
Shiba Inu(SHIB)
€0.000011
0.02%
Pepe(PEPE)
€0.000007
3.61%
Scroll to Top