'RomCom' APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Tor
ID: 2d69f45b-1ee6-562b-b09f-2dd9441f1927
STIX ID: report--2d69f45b-1ee6-562b-b09f-2dd9441f1927
Feed Name: Dark Reading
Threat Score
In October, researchers observed the RomCom APT using a chain of two zero-days — a critical Firefox/Tor use-after-free (CVE-2024-9680) and a Windows Task Scheduler privilege escalation (CVE-2024-49039) — to deliver a RomCom backdoor via malicious websites without user interaction; both flaws were patched quickly (Firefox on Oct. 9 and Windows on Nov. 12), and most tracked victims were in North America and Europe across corporate targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
