RomCom Backdoor Attacks Use Zero-Day Exploits in Mozilla and Windows (CVE-2024-9680 & CVE-2024-49039

Share:
Aspect Details
Threat Actors RomCom, suspected ties to Russia, also known as Tropical Scorpius, Storm-0978, or UNC2596.
Campaign Overview Exploited zero-day vulnerabilities (CVE-2024-9680 & CVE-2024-49039) to deploy RomCom backdoor via zero-click exploits.
Target Regions (Or Victims) Primarily Europe and North America, with up to 250 affected targets between October 10 – November 4, 2024.
Methodology Fake domains, zero-click exploits, privilege escalation, and stealthy redirection via malicious websites.
Product Targeted Mozilla Firefox, Thunderbird, Tor browsers, and Microsoft Windows Task Scheduler.
Malware Reference RomCom backdoor
Tools Used Fake domains (e.g., redircorrectiv[.]com), Reflective DLL Injection, C2 servers like journalctd[.]live.
Vulnerabilities Exploited CVE-2024-9680 (Use-After-Free in Firefox), CVE-2024-49039 (Elevation of Privilege in Windows Task Scheduler).
TTPs Phishing domains, zero-click exploit chain, DLL injection, and system compromise via backdoor.
Attribution RomCom threat group, suspected Russian ties.
Recommendations Monitor for IOCs, use SOCRadar’s Vulnerability Intelligence to track CVEs, and implement Brand Protection for domain detection.
Source SOCRadar

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:02 am, Jan 18, 2025
weather icon 2°C
L: 1° | H: 3°
overcast clouds
Humidity: 89 %
Pressure: 1031 mb
Wind: 5 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 6 km
Sunrise: 7:56 am
Sunset: 4:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
1° | 3°°C 0 mm 0% 4 mph 90 % 1030 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
1° | 5°°C 0 mm 0% 7 mph 93 % 1024 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 8°°C 0.26 mm 26% 6 mph 97 % 1019 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 95 % 1019 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
4° | 7°°C 1 mm 100% 4 mph 99 % 1012 mb 0 mm/h
Today 12:00 pm
weather icon
2° | 5°°C 0 mm 0% 3 mph 89 % 1030 mb 0 mm/h
Today 3:00 pm
weather icon
3° | 6°°C 0 mm 0% 3 mph 82 % 1029 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 88 % 1027 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 3 mph 90 % 1025 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 89 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 91 % 1022 mb 0 mm/h
Tomorrow 6:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 93 % 1021 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0 mm 0% 4 mph 83 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,070.84
0.77%
Ethereum(ETH)
€3,154.02
-5.07%
XRP(XRP)
€3.00
-6.19%
Tether(USDT)
€0.97
-0.03%
Solana(SOL)
€234.14
11.24%
Dogecoin(DOGE)
€0.382576
-5.17%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000022
-6.49%
Pepe(PEPE)
€0.000018
-6.48%
Peanut the Squirrel(PNUT)
€0.52
-15.44%
Scroll to Top