Russia-aligned RomCom hackers exploited Firefox and Windows zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-9680 | Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile). Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability. | 9.8 | 23% | KEV ransomware |
| masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments) |
Full article572 words · extracted from therecord.media · click to collapse
Russia-linked hackers exploited two zero-day vulnerabilities in Mozilla and Microsoft products to target victims in Europe and North America, researchers have found. RomCom, also tracked as Storm-0978, is known for targeting defense and government entities around the world. It engages in both ransomware and espionage activities and is attributed to Russian-speaking threat actors. The group derives its name from the custom malware it has been using since at least 2022. In their latest campaign, analyzed by the Slovak-based cybersecurity firm ESET, the hackers exploited a serious security flaw in Mozilla’s Firefox browser, tracked as CVE-2024-9680, as well as a vulnerability in Microsoft products for Windows, tracked as CVE‑2024‑49039. Exploiting the Firefox vulnerability could allow attackers to execute malicious code within the browser’s content process — an environment where web content is loaded and rendered. The exploit requires no user interaction and can be executed over the network with low complexity. Earlier in October, the Tor anonymity network issued an emergency patch to address this flaw, warning that it could allow attackers to take control of the Tor Browser. Another vulnerability was found in a Windows tool used to automate tasks such as running scripts or programs at specific times. According to ESET, it could allow the attackers to execute code outside the Firefox and Tor Browser sandboxes. Successful exploitation of the vulnerabilities could allow hackers to infect victims’ devices with the RomCom backdoor, a tool capable of executing commands and downloading additional modules to the victim’s machine. Both Mozilla and Microsoft have since patched the vulnerabilities. The hackers deliver their backdoor via a fake website that redirects potential victims to a server hosting the exploit, which then executes the malware, researchers said. While it remains unclear how victims are directed to the fake website, visiting it with a vulnerable browser automatically downloads and runs the malware without requiring any user action. According to ESET’s analysis, between October and November the majority of potential victims who accessed the exploit-hosting websites were located in Europe and North America. The number of targets varied from a single victim in some countries to as many as 250 in others. “Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET said. “This level of sophistication demonstrates the threat actor’s capability and intent to develop stealthy attack methods.” RomCom has been actively targeting anti-Russian entities since Moscow’s invasion of Ukraine. Earlier in October, high-profile Ukrainian government entities and unidentified Polish organizations were reportedly targeted with an updated version of the malware. The goal of these attacks is to establish long-term access to victims' systems and exfiltrate data “of strategic interest.” Researchers have also noted that the hackers may later deploy ransomware on compromised devices to pursue financial gain. Last year, RomCom-linked hackers targeted Ukraine and its allies ahead of a NATO summit in Lithuania, likely leveraging the event’s high profile to infect guests with malicious software. RomCom has also been used against Ukrainian military organizations, IT companies, and politicians collaborating with Western nations, according to BlackBerry. Other victims included a U.S.-based healthcare company providing humanitarian aid to Ukrainian refugees receiving medical assistance in the U.S.
No previous article
No new articles
James Reddick
has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-romcom-hackers-zero-days