RomCom hackers exploit Firefox and Windows zero-days to deploy backdoor

helpnetsecurity.com November 26, 2024, 11:01 AM UTC

The Russia-aligned hacking group RomCom exploited two zero-day vulnerabilities earlier this year: a flaw in Firefox and one in Windows Task Scheduler. This allowed them to execute code without any user interaction, targeting victims mainly in Europe and North America. The attack involved a fake website that redirected users to a server hosting the exploit. If triggered, the exploit would download and execute RomCom's backdoor, enabling the hackers to run commands on the victims' computers. Mozilla and Microsoft quickly released fixes for the vulnerabilities after they were reported. ESET has provided detailed analyses of the vulnerabilities and the attack methods used by RomCom, which has a history of targeting various sectors, including government and defense.


With a significance score of 3.6, this news ranks in the top 21% of today's 13069 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 8000 minimalists.