RomCom exploits Firefox and Windows zero days in the wild
ID: 84e45ee2-692f-5b50-be1d-95b886eaa8fe
STIX ID: report--84e45ee2-692f-5b50-be1d-95b886eaa8fe
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET discovered an in-the-wild exploit chain used by the Russia-aligned actor RomCom that abused a Firefox animation timeline use-after-free (CVE-2024-9680) and a Windows Task Scheduler privilege escalation (CVE-2024-49039) to escape the browser sandbox and install a RomCom backdoor; both vulnerabilities were patched by Mozilla and Microsoft shortly after disclosure, and the report provides technical analysis, IoCs, targeted sectors, and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
