RomCom hackers chained Firefox and Windows zero-days to deliver backdoor

Teilen:

Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows Task Scheduler, as zero-days earlier this year.

“Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET researchers said.

The campaign leveraging the zero-click exploit

CVE-2024-9680 allowed the attackers to execute code in the restricted context of the browser and CVE-2024-49039 allowed it to run outside Firefox’s sandbox, and it all happened without the victims interacting with the websites in any way.

RomCom CVE-2024-9680 CVE-2024-49039

Exploit chain to compromise the victim (Source: ESET)

ESET researcher Damien Schaeffer, who discovered both vulnerabilities, said that the compromise chain was composed of a fake website that redirects the potential victim to the server hosting the zero-click exploit and, if the exploit was triggered, – shellcode that downloads and executes the RomCom backdoor is executed.

He also shared that they don’t know how the link to the fake website was distributed.

“According to our telemetry, from October 10, 2024 to November 4th, 2024, potential victims who visited websites hosting the exploit were located mainly in Europe and North America,” ESET shared, and noted that the campaign seems to have been widespread.

RomCom’s backdoor is capable of executing commands and downloading additional modules on the victims’ computer.

“This level of sophistication demonstrates the threat actor’s intent and means to obtain or develop stealthy capabilities,” the company added.

Schaeffer discovered the Firefox vulnerability on October 8 and immediately reported it to Mozilla, which shipped the fix for Firefox and Firefox ESR within 25 hours. Two days later, a fix for Mozilla’s Thunderbird email client was also pushed out, but the company noted that vulnerabilities like CVE-2024-9680 “cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail.”

Soon after, the Tor Project fixed CVE-2024-9680 in various versions of the Tor Browser and Tails operating system, which uses a modified version of Tor Browser.

Microsoft released a fix for CVE-2024-49039 on November 12.

ESET has released a root cause analysis of the two vulnerabilities, a technical analysis of the shellcode, and indicators of compromise related to this campaign.

About RomCom

RomCom (aka Storm-0978, Tropical Scorpius, or UNC2596) is a Russia-aligned threat actor that engages in both opportunistic campaigns against selected business verticals and targeted espionage operations.

“This is at least the second time that RomCom has been caught exploiting a significant zero-day vulnerability in the wild, after the abuse of CVE-2023-36884 via Microsoft Word in June 2023,” the company shared.

“In 2024, ESET discovered cyberespionage and cybercrime operations of RomCom against governmental entities, defense, and energy sectors in Ukraine, the pharmaceutical and insurance sectors in the US; the legal sector in Germany; and governmental entities in Europe.”

Zeljka Zorz

 

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:12 am, Juli 14, 2025
Wetter-Symbol 19°C
L: 17° | H: 20°
light rain
Luftfeuchtigkeit: 74 %
Druck: 1011 mb
Wind: 5 mph SSE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.24 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:59 am
Sonnenuntergang: 9:12 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 20°°C 0 mm 0% 18 mph 76 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 20°°C 1 mm 100% 15 mph 78 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
14° | 27°°C 0.2 mm 20% 14 mph 73 % 1017 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
18° | 26°°C 1 mm 100% 8 mph 80 % 1017 mb 0 mm/h
Fr. Juli 18 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 12 mph 79 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 9 mph 76 % 1011 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 11 mph 59 % 1012 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 18 mph 28 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 15 mph 30 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 45 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 61 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 72 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€102,450.71
1.74%
Ethereum(ETH)
€2,568.36
1.64%
XRP(XRP)
€2.47
4.21%
Fesseln(USDT)
€0.86
0.00%
Solana(SOL)
€141.15
2.36%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.172468
1.83%
Shiba Inu(SHIB)
€0.000012
2.16%
Pepe(PEPE)
€0.000011
2.78%
Peanut das Eichhörnchen(PNUT)
€0.244556
5.81%
Nach oben scrollen