RomCom hackers chained Firefox and Windows zero-days to deliver backdoor

Share:

Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows Task Scheduler, as zero-days earlier this year.

“Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET researchers said.

The campaign leveraging the zero-click exploit

CVE-2024-9680 allowed the attackers to execute code in the restricted context of the browser and CVE-2024-49039 allowed it to run outside Firefox’s sandbox, and it all happened without the victims interacting with the websites in any way.

RomCom CVE-2024-9680 CVE-2024-49039

Exploit chain to compromise the victim (Source: ESET)

ESET researcher Damien Schaeffer, who discovered both vulnerabilities, said that the compromise chain was composed of a fake website that redirects the potential victim to the server hosting the zero-click exploit and, if the exploit was triggered, – shellcode that downloads and executes the RomCom backdoor is executed.

He also shared that they don’t know how the link to the fake website was distributed.

“According to our telemetry, from October 10, 2024 to November 4th, 2024, potential victims who visited websites hosting the exploit were located mainly in Europe and North America,” ESET shared, and noted that the campaign seems to have been widespread.

RomCom’s backdoor is capable of executing commands and downloading additional modules on the victims’ computer.

“This level of sophistication demonstrates the threat actor’s intent and means to obtain or develop stealthy capabilities,” the company added.

Schaeffer discovered the Firefox vulnerability on October 8 and immediately reported it to Mozilla, which shipped the fix for Firefox and Firefox ESR within 25 hours. Two days later, a fix for Mozilla’s Thunderbird email client was also pushed out, but the company noted that vulnerabilities like CVE-2024-9680 “cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail.”

Soon after, the Tor Project fixed CVE-2024-9680 in various versions of the Tor Browser and Tails operating system, which uses a modified version of Tor Browser.

Microsoft released a fix for CVE-2024-49039 on November 12.

ESET has released a root cause analysis of the two vulnerabilities, a technical analysis of the shellcode, and indicators of compromise related to this campaign.

About RomCom

RomCom (aka Storm-0978, Tropical Scorpius, or UNC2596) is a Russia-aligned threat actor that engages in both opportunistic campaigns against selected business verticals and targeted espionage operations.

“This is at least the second time that RomCom has been caught exploiting a significant zero-day vulnerability in the wild, after the abuse of CVE-2023-36884 via Microsoft Word in June 2023,” the company shared.

“In 2024, ESET discovered cyberespionage and cybercrime operations of RomCom against governmental entities, defense, and energy sectors in Ukraine, the pharmaceutical and insurance sectors in the US; the legal sector in Germany; and governmental entities in Europe.”

Zeljka Zorz

 

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:58 am, Jun 30, 2025
weather icon 19°C
L: 17° | H: 20°
overcast clouds
Humidity: 80 %
Pressure: 1021 mb
Wind: 2 mph SE
Wind Gust: 3 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 20°°C 0 mm 0% 9 mph 80 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
22° | 33°°C 0 mm 0% 10 mph 68 % 1016 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
16° | 23°°C 0.65 mm 65% 10 mph 82 % 1021 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 24°°C 0 mm 0% 10 mph 84 % 1026 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 25°°C 0 mm 0% 13 mph 57 % 1027 mb 0 mm/h
Today 4:00 am
weather icon
18° | 19°°C 0 mm 0% 3 mph 80 % 1021 mb 0 mm/h
Today 7:00 am
weather icon
19° | 20°°C 0 mm 0% 4 mph 77 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
24° | 26°°C 0 mm 0% 6 mph 60 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 7 mph 32 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 9 mph 26 % 1015 mb 0 mm/h
Today 7:00 pm
weather icon
29° | 29°°C 0 mm 0% 9 mph 31 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
27° | 27°°C 0 mm 0% 2 mph 42 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
24° | 24°°C 0 mm 0% 4 mph 56 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,630.59
1.21%
Ethereum(ETH)
€2,138.08
3.09%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.88
0.47%
Solana(SOL)
€130.03
1.75%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.143290
3.03%
Shiba Inu(SHIB)
€0.000010
1.41%
Pepe(PEPE)
€0.000009
6.19%
Scroll to Top