RomCom’ APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor

Teilen:

The innocuously named Russian-sponsored cyber threat actor has combined critical and serious vulnerabilities in Windows and Firefox products in a zero-click code execution exploit.

For a brief window of time in October, Russian hackers had the ability to launch arbitrary code against anyone in the world using Firefox or Tor.

On Oct. 8, researchers from ESET first spotted malicious files on a server managed by the Russian advanced persistent threat (APT) RomCom (aka Storm-0978, Tropical Scorpius, UNC2596). The files had gone online just five days earlier, on Oct. 3. Analysis showed that they leveraged two zero-day vulnerabilities: one affecting Mozilla software, the other Windows. The result: an exploit that spread the RomCom backdoor to anyone who visited an infected website, no clicks required.

Luckily, both issues were remediated quickly. “The attackers only had a really small window to try to compromise computers,” explains Romain Dumont, malware researcher with ESET. “Yes, there was a zero-day vulnerability. But, still, it was patched really fast.”

Dark Reading has reached out to Mozilla for comment on this story.

A Zero-Day in Firefox & Tor

The first of the two vulnerabilities, CVE-2024-9680, is a use-after-free opportunity in Firefox animation timelines — the browser mechanism that handles how animations play out based on user interactions with websites. Its power to afford attackers arbitrary command execution earned it a “critical” 9.8 rating from the Common Vulnerability Scoring System (CVSS). 

Nate Nelson

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:48 am, Feb. 1, 2025
Wetter-Symbol 5°C
L: 4° | H: 5°
overcast clouds
Luftfeuchtigkeit: 88 %
Druck: 1030 mb
Wind: 6 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:38 am
Sonnenuntergang: 4:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 5°°C 0 mm 0% 6 mph 88 % 1030 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 6 mph 84 % 1025 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 5 mph 85 % 1026 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
4° | 9°°C 1 mm 100% 12 mph 93 % 1026 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0.8 mm 80% 9 mph 91 % 1046 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 88 % 1030 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 6 mph 83 % 1030 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 76 % 1029 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 79 % 1027 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 85 % 1026 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 5 mph 84 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 83 % 1023 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 82 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€98,445.33
-2.03%
Ethereum(ETH)
€3,152.72
0.87%
XRP(XRP)
€2.92
-1.34%
Fesseln(USDT)
€0.97
-0.01%
Solana(SOL)
€221.54
-2.40%
USDC(USDC)
€0.97
0.00%
Dogecoin(DOGE)
€0.313335
-0.66%
Shiba Inu(SHIB)
€0.000018
1.31%
Pepe(PEPE)
€0.000013
4.26%
Nach oben scrollen