logo

Firefox and Windows zero-days exploited by Russian RomCom hackers

ID: b3c40ac5-c5e2-5b96-9d20-d4fc75244361

STIX ID: report--b3c40ac5-c5e2-5b96-9d20-d4fc75244361

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-11-26

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Russian-based RomCom chained two zero-day vulnerabilities (Firefox CVE-2024-9680 and Windows Task Scheduler CVE-2024-49039) to achieve remote code execution and privilege escalation, delivering a RomCom backdoor to victims who visited attacker-controlled sites. ESET telemetry indicates active exploitation against Firefox and Tor Browser users across Europe and North America, affecting organizations in government, defense, energy, pharmaceuticals, and insurance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.