Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » RomCom exploits Firefox and Windows Zero-Day flaws in sophisticated cyberattacks
Global Security

RomCom exploits Firefox and Windows Zero-Day flaws in sophisticated cyberattacks

AdminBy AdminNovember 26, 2024No Comments3 Mins Read
Zero-Day Firefox and Windows Flaws
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 26, 2024Ravi LakshmananVulnerability / Cybercrime

Firefox and Windows Zero-Day Flaws

Russian threat actor known as RomCom was linked to the exploitation of two zero-day security flaws, one in Mozilla Firefox and the other in Microsoft Windows, in attacks aimed at delivering a backdoor of the same name to victim systems.

“In a successful attack, when the victim views a web page containing the exploit, the adversary can run arbitrary code – without the need for user interaction (zero click) – which in this case resulted in the RomCom backdoor being installed on the victim’s computer,” it said ESET messages the report shared with The Hacker News.

The vulnerabilities in question are listed below –

  • CVE-2024-9680 (CVSS Score: 9.8) – Use-after-free vulnerability in the Firefox animation component (Fixed by Mozilla October 2024)
  • CVE-2024-49039 (CVSS Score: 8.8) – Windows Task Scheduler Elevation of Privilege Vulnerability (Fixed by Microsoft November 2024)
Cyber ​​security

RomComalso known as Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, and Void Rabisu, has a track record of conducting both cybercrime and espionage operations since at least 2022.

These attacks are characterized by the deployment of the RomCom RAT, an actively supported piece of malware capable of executing commands and loading additional modules onto the victim’s machine.

The chain of attacks discovered by a Slovak cyber security company involved the use of a fake website (economistjournal(.)cloud) responsible for redirecting potential victims to a server (redjournal(.)cloud) hosting a malicious payload that, in its queue, combines both flaws to achieve code execution and reject the RomCom RAT.

Firefox and Windows Zero-Day Flaws

It is currently unknown how the links to the fake site are distributed, but it has been discovered that the exploit is triggered when the site is visited from a vulnerable version of the Firefox browser.

“When a victim using a vulnerable browser visits a web page that serves this exploit, the vulnerability is triggered and shellcode is executed in content process“, ESET explained.

“The shellcode consists of two parts: the first retrieves the second from memory and marks the pages containing it as executable, and the second implements the PE loader, based on the Shellcode Reflective DLL Injection open source project (RDI).”

The result is a sandboxed exit for Firefox that eventually causes the RomCom RAT to download and run on the compromised system. This is achieved using a built-in library (“PocLowIL”) that is designed to break out of the browser’s sandboxed content process by exploiting a flaw in the Windows Task Scheduler to gain elevated privileges.

Telemetry data collected by ESET shows that the majority of victims who visited the site with the exploit were located in Europe and North America.

Cyber ​​security

The fact that CVE-2024-49039 was also independently discovered and reported to Microsoft by Google’s Threat Analysis Group (TAG) suggests that more than one threat actor could have used it as a zero-day.

It’s also worth noting that this is the second time a RomCom has been caught exploiting a zero-day vulnerability in the wild after being abused CVE-2023-36884 via Microsoft Word in June 2023.

“The combination of two zero-day vulnerabilities armed RomCom with an exploit that does not require user interaction,” ESET said. “This level of sophistication indicates the will and means of the threat actor to obtain or develop latent capabilities.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.