RomCom Hackers Exploit Firefox and Windows Zero-Days in Cyberattacks

1 min read
Source: The Hacker News
RomCom Hackers Exploit Firefox and Windows Zero-Days in Cyberattacks
Photo: The Hacker News
TL;DR Summary

The Russia-aligned threat actor RomCom has exploited zero-day vulnerabilities in Mozilla Firefox and Microsoft Windows to deliver a backdoor on victim systems. The vulnerabilities, CVE-2024-9680 in Firefox and CVE-2024-49039 in Windows, allow for zero-click code execution and privilege escalation, respectively. RomCom used a fake website to redirect victims to a server hosting the malicious payload, leading to the installation of RomCom RAT. The attacks primarily targeted users in Europe and North America, highlighting RomCom's sophisticated cybercrime and espionage capabilities.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

85%

54279 words

Want the full story? Read the original article

Read on The Hacker News