RomCom’ APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor

Share:

The innocuously named Russian-sponsored cyber threat actor has combined critical and serious vulnerabilities in Windows and Firefox products in a zero-click code execution exploit.

For a brief window of time in October, Russian hackers had the ability to launch arbitrary code against anyone in the world using Firefox or Tor.

On Oct. 8, researchers from ESET first spotted malicious files on a server managed by the Russian advanced persistent threat (APT) RomCom (aka Storm-0978, Tropical Scorpius, UNC2596). The files had gone online just five days earlier, on Oct. 3. Analysis showed that they leveraged two zero-day vulnerabilities: one affecting Mozilla software, the other Windows. The result: an exploit that spread the RomCom backdoor to anyone who visited an infected website, no clicks required.

Luckily, both issues were remediated quickly. “The attackers only had a really small window to try to compromise computers,” explains Romain Dumont, malware researcher with ESET. “Yes, there was a zero-day vulnerability. But, still, it was patched really fast.”

Dark Reading has reached out to Mozilla for comment on this story.

A Zero-Day in Firefox & Tor

The first of the two vulnerabilities, CVE-2024-9680, is a use-after-free opportunity in Firefox animation timelines — the browser mechanism that handles how animations play out based on user interactions with websites. Its power to afford attackers arbitrary command execution earned it a “critical” 9.8 rating from the Common Vulnerability Scoring System (CVSS). 

Nate Nelson

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:37 am, Jul 13, 2025
weather icon 15°C
L: 13° | H: 17°
few clouds
Humidity: 88 %
Pressure: 1014 mb
Wind: 3 mph N
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 11%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:58 am
Sunset: 9:13 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 17°°C 0 mm 0% 6 mph 83 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 27°°C 0 mm 0% 15 mph 72 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 22°°C 0.94 mm 94% 15 mph 79 % 1016 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
15° | 26°°C 0.4 mm 40% 13 mph 90 % 1016 mb 0 mm/h
Thu Jul 17 10:00 pm
weather icon
19° | 25°°C 0 mm 0% 7 mph 61 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
16° | 17°°C 0 mm 0% 5 mph 83 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
21° | 24°°C 0 mm 0% 4 mph 62 % 1013 mb 0 mm/h
Today 1:00 pm
weather icon
28° | 28°°C 0 mm 0% 3 mph 37 % 1011 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 2 mph 30 % 1010 mb 0 mm/h
Today 7:00 pm
weather icon
28° | 28°°C 0 mm 0% 4 mph 31 % 1009 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 23°°C 0 mm 0% 6 mph 47 % 1010 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 5 mph 52 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 20°°C 0 mm 0% 6 mph 61 % 1010 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,759.93
-0.03%
Ethereum(ETH)
€2,528.58
-0.38%
XRP(XRP)
€2.37
-1.52%
Tether(USDT)
€0.86
-0.01%
Solana(SOL)
€137.89
-1.42%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.169391
-3.31%
Shiba Inu(SHIB)
€0.000011
-1.81%
Pepe(PEPE)
€0.000010
-1.43%
Peanut the Squirrel(PNUT)
€0.246209
7.19%
Scroll to Top