logo

RomCom exploits Firefox and Windows zero days in the wild

ID: 84e45ee2-692f-5b50-be1d-95b886eaa8fe

STIX ID: report--84e45ee2-692f-5b50-be1d-95b886eaa8fe

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-11-26

Date Updated: 2026-05-01

...
...

ESET discovered an in-the-wild exploit chain used by the Russia-aligned actor RomCom that abused a Firefox animation timeline use-after-free (CVE-2024-9680) and a Windows Task Scheduler privilege escalation (CVE-2024-49039) to escape the browser sandbox and install a RomCom backdoor; both vulnerabilities were patched by Mozilla and Microsoft shortly after disclosure, and the report provides technical analysis, IoCs, targeted sectors, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.