RomCom’ APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor

Teilen:

The innocuously named Russian-sponsored cyber threat actor has combined critical and serious vulnerabilities in Windows and Firefox products in a zero-click code execution exploit.

For a brief window of time in October, Russian hackers had the ability to launch arbitrary code against anyone in the world using Firefox or Tor.

On Oct. 8, researchers from ESET first spotted malicious files on a server managed by the Russian advanced persistent threat (APT) RomCom (aka Storm-0978, Tropical Scorpius, UNC2596). The files had gone online just five days earlier, on Oct. 3. Analysis showed that they leveraged two zero-day vulnerabilities: one affecting Mozilla software, the other Windows. The result: an exploit that spread the RomCom backdoor to anyone who visited an infected website, no clicks required.

Luckily, both issues were remediated quickly. “The attackers only had a really small window to try to compromise computers,” explains Romain Dumont, malware researcher with ESET. “Yes, there was a zero-day vulnerability. But, still, it was patched really fast.”

Dark Reading has reached out to Mozilla for comment on this story.

A Zero-Day in Firefox & Tor

The first of the two vulnerabilities, CVE-2024-9680, is a use-after-free opportunity in Firefox animation timelines — the browser mechanism that handles how animations play out based on user interactions with websites. Its power to afford attackers arbitrary command execution earned it a “critical” 9.8 rating from the Common Vulnerability Scoring System (CVSS). 

Nate Nelson

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:36 am, Juni 27, 2025
Wetter-Symbol 19°C
L: 18° | H: 21°
klarer Himmel
Luftfeuchtigkeit: 70 %
Druck: 1020 mb
Wind: 6 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 9%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 21°°C 0 mm 0% 13 mph 70 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 11 mph 91 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 31°°C 0 mm 0% 8 mph 76 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 34°°C 0.2 mm 20% 8 mph 64 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
21° | 33°°C 0 mm 0% 11 mph 68 % 1016 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 70 % 1020 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
21° | 25°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 27°°C 0 mm 0% 13 mph 49 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 13 mph 39 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 11 mph 68 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 9 mph 85 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 91 % 1022 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 8 mph 82 % 1023 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,310.46
-1.04%
Ethereum(ETH)
€2,087.03
-2.04%
Fesseln(USDT)
€0.86
-0.01%
XRP(XRP)
€1.79
-4.60%
Solana(SOL)
€120.68
-2.88%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.137772
-2.30%
Shiba Inu(SHIB)
€0.000009
-3.59%
Pepe(PEPE)
€0.000008
-3.10%
Nach oben scrollen