Cybersecurity experts have discovered two previously unknown zero-day vulnerabilities being actively exploited by the hacking group RomCom, which is associated with Russia. These vulnerabilities target both Firefox browser users and Windows device owners in Europe and North America.
RomCom is notorious for carrying out cyberattacks and other malicious digital activities on behalf of the Russian government. Recently, the group was linked to a ransomware attack targeting Japanese tech giant Casio. It is also known for its aggressive stance against organizations supporting Ukraine, a country invaded by Russia in 2014.
According to experts from the security firm ESET, RomCom combined two zero-day vulnerabilities (so named because developers had no time to address them before they were exploited) to create a “zero-click” exploit. This type of attack enables hackers to remotely install malware on a victim’s device without requiring any user interaction.
“The sophistication of this attack reflects the group’s skill and intent to develop stealthy intrusion methods,” wrote ESET researchers Damien Schaeffer and Romain Dumont in a blog post on Monday.
To trigger the exploit, victims only need to visit a malicious website controlled by the hackers, with no further action required. Once the attack is executed, malware known as the RomCom backdoor is installed on the device, granting hackers full access to it.
Schaeffer told TechCrunch that the potential number of victims in RomCom’s “large-scale” campaign ranges from a single victim per country to 250 people, with most of the targets located in Europe and North America.
Mozilla addressed the Firefox vulnerability on October 9, just one day after ESET alerted the browser’s developers. Similarly, the Tor Project, which uses Firefox’s codebase for its Tor Browser, also fixed the issue, though ESET reported no evidence that the Tor Browser was targeted during the campaign.
Microsoft resolved the Windows vulnerability on November 12. Google’s Threat Analysis Group, which investigates state-sponsored cyberattacks, reported the issue to Microsoft, suggesting that the exploit may have been used in other government-backed hacking campaigns.
By: Nestor Castillo, ForAllTechNews Director
