logo

Firefox and Windows zero days chained to deliver the RomCom backdoor

ID: fe48eff1-2043-5ec4-bacc-e4713af0ce4c

STIX ID: report--fe48eff1-2043-5ec4-bacc-e4713af0ce4c

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-11-26

Date Updated: 2026-05-01

...
...

ESET researchers discovered that the RomCom group exploited two zero-day flaws—CVE-2024-9680 in Firefox/Tor/Thunderbird and CVE-2024-49039 in Windows—chained as a zero-click exploit to install the RomCom backdoor which can execute commands and download additional modules; both vulnerabilities were later patched (Firefox on Oct 9, 2024; Windows on Nov 12, 2024).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.