logo

'RomCom' APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor

ID: 2d69f45b-1ee6-562b-b09f-2dd9441f1927

STIX ID: report--2d69f45b-1ee6-562b-b09f-2dd9441f1927

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-11-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

In October, researchers observed the RomCom APT using a chain of two zero-days — a critical Firefox/Tor use-after-free (CVE-2024-9680) and a Windows Task Scheduler privilege escalation (CVE-2024-49039) — to deliver a RomCom backdoor via malicious websites without user interaction; both flaws were patched quickly (Firefox on Oct. 9 and Windows on Nov. 12), and most tracked victims were in North America and Europe across corporate targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.