Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » RomCom exploits Firefox and Windows Zero-Day flaws in sophisticated cyberattacks
Global Security

RomCom exploits Firefox and Windows Zero-Day flaws in sophisticated cyberattacks

AdminBy AdminNovember 26, 2024No Comments3 Mins Read
Zero-Day Firefox and Windows Flaws
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 26, 2024Ravi LakshmananVulnerability / Cybercrime

Firefox and Windows Zero-Day Flaws

Russian threat actor known as RomCom was linked to the exploitation of two zero-day security flaws, one in Mozilla Firefox and the other in Microsoft Windows, in attacks aimed at delivering a backdoor of the same name to victim systems.

“In a successful attack, when the victim views a web page containing the exploit, the adversary can run arbitrary code – without the need for user interaction (zero click) – which in this case resulted in the RomCom backdoor being installed on the victim’s computer,” it said ESET messages the report shared with The Hacker News.

The vulnerabilities in question are listed below –

  • CVE-2024-9680 (CVSS Score: 9.8) – Use-after-free vulnerability in the Firefox animation component (Fixed by Mozilla October 2024)
  • CVE-2024-49039 (CVSS Score: 8.8) – Windows Task Scheduler Elevation of Privilege Vulnerability (Fixed by Microsoft November 2024)
Cyber ​​security

RomComalso known as Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, and Void Rabisu, has a track record of conducting both cybercrime and espionage operations since at least 2022.

These attacks are characterized by the deployment of the RomCom RAT, an actively supported piece of malware capable of executing commands and loading additional modules onto the victim’s machine.

The chain of attacks discovered by a Slovak cyber security company involved the use of a fake website (economistjournal(.)cloud) responsible for redirecting potential victims to a server (redjournal(.)cloud) hosting a malicious payload that, in its queue, combines both flaws to achieve code execution and reject the RomCom RAT.

Firefox and Windows Zero-Day Flaws

It is currently unknown how the links to the fake site are distributed, but it has been discovered that the exploit is triggered when the site is visited from a vulnerable version of the Firefox browser.

“When a victim using a vulnerable browser visits a web page that serves this exploit, the vulnerability is triggered and shellcode is executed in content process“, ESET explained.

“The shellcode consists of two parts: the first retrieves the second from memory and marks the pages containing it as executable, and the second implements the PE loader, based on the Shellcode Reflective DLL Injection open source project (RDI).”

The result is a sandboxed exit for Firefox that eventually causes the RomCom RAT to download and run on the compromised system. This is achieved using a built-in library (“PocLowIL”) that is designed to break out of the browser’s sandboxed content process by exploiting a flaw in the Windows Task Scheduler to gain elevated privileges.

Telemetry data collected by ESET shows that the majority of victims who visited the site with the exploit were located in Europe and North America.

Cyber ​​security

The fact that CVE-2024-49039 was also independently discovered and reported to Microsoft by Google’s Threat Analysis Group (TAG) suggests that more than one threat actor could have used it as a zero-day.

It’s also worth noting that this is the second time a RomCom has been caught exploiting a zero-day vulnerability in the wild after being abused CVE-2023-36884 via Microsoft Word in June 2023.

“The combination of two zero-day vulnerabilities armed RomCom with an exploit that does not require user interaction,” ESET said. “This level of sophistication indicates the will and means of the threat actor to obtain or develop latent capabilities.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.