Firefox- und Windows-Zero-Days werden von russischen RomCom-Hackern ausgenutzt

Teilen:

​Russian-based RomCom cybercrime group chained two zero-day vulnerabilities in recent attacks targeting Firefox and Tor Browser users across Europe and North America.

The first flaw (CVE-2024-9680) is a use-after-free bug in Firefox’s animation timeline feature that allows code execution in the web browser’s sandbox. Mozilla patched this vulnerability on October 9, 2024, one day after ESET reported it.

The second zero-day exploited in this campaign is a privilege escalation flaw (CVE-2024-49039) in the Windows Task Scheduler service, allowing attackers to execute code outside the Firefox sandbox. Microsoft addressed this security vulnerability earlier this month, on November 12.

RomCom abused the two vulnerabilities as a zero-day chain exploit, which helped them gain remote code execution without requiring user interaction. Their targets only had to visit an attacker-controlled and maliciously crafted website that downloaded and executed the RomCom backdoor on their system.

Based on the name of one of the JavaScript exploits used in the attacks (main-tor.js), the threat actors also targeted Tor Browser users (versions 12 and 13, according to ESET’s analysis).

RomCom attack flow
RomCom attack flow (ESET)

“The compromise chain is composed of a fake website that redirects the potential victim to the server hosting the exploit, and should the exploit succeed, shellcode is executed that downloads and executes the RomCom backdoor,” said ESET researcher Damien Schaeffer.

“While we don’t know how the link to the fake website is distributed, however, if the page is reached using a vulnerable browser, a payload is dropped and executed on the victim’s computer with no user interaction required.”

Once deployed on a victim’s device, this malware enabled the attackers to run commands and deploy additional payloads.

“Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction. This level of sophistication shows the threat actor’s will and means to obtain or develop stealthy capabilities,” ESET added.

Additionally, the number of successful exploitation attempts in these attacks that ended with the RomCom backdoor being deployed on victims’ devices led ESET to believe this was a widespread campaign.

“The number of potential targets runs from a single victim per country to as many as 250, according to ESET telemetry,” ESET said.

RomCom victims
RomCom victims heatmap (ESET)

This isn’t the first time RomCom has exploited a zero-day in its attacks. In July 2023, its operators exploited a zero-day (CVE-2023-36884) in multiple Windows and Office products to attack organizations attending the NATO Summit in Vilnius, Lithuania.

RomCom (also tracked as Storm-0978, Tropical Scorpius, or UNC2596) has been linked to financially motivated campaigns and orchestrated ransomware and extortion attacks alongside credential theft (likely aimed at supporting intelligence operations).

The threat group was also linked to the Industrial Spy ransomware operation, which has since switched to Underground ransomware.

According to ESET, RomCom is now also targeting organizations in Ukraine, Europe, and North America for espionage attacks across various industries, including government, defense, energy, pharmaceuticals, and insurance.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:51 am, Juni 17, 2025
Wetter-Symbol 22°C
L: 20° | H: 23°
wenige Wolken
Luftfeuchtigkeit: 61 %
Druck: 1026 mb
Wind: 8 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 21%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 10 mph 61 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 8 mph 76 % 1026 mb 0 mm/h
Do. Juni 19 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 11 mph 82 % 1028 mb 0 mm/h
Fr. Juni 20 10:00 pm
Wetter-Symbol
15° | 25°°C 0 mm 0% 11 mph 71 % 1028 mb 0 mm/h
Sa. Juni 21 10:00 pm
Wetter-Symbol
15° | 28°°C 0 mm 0% 10 mph 79 % 1026 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 22°°C 0 mm 0% 7 mph 61 % 1026 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 24°°C 0 mm 0% 7 mph 54 % 1026 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 27°°C 0 mm 0% 8 mph 41 % 1025 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 10 mph 42 % 1024 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 53 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 5 mph 67 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 4 mph 76 % 1025 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 3 mph 72 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,273.23
-0.47%
Ethereum(ETH)
€2,228.82
-2.01%
Fesseln(USDT)
€0.87
0.02%
XRP(XRP)
€1.92
0.97%
Solana(SOL)
€131.47
-3.17%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.149753
-2.76%
Shiba Inu(SHIB)
€0.000010
-3.01%
Pepe(PEPE)
€0.000010
-7.78%
Nach oben scrollen