Russian Hackers Exploit Firefox and Windows Zero-Days in Broad Campaign

A Russian-linked hacking group uses two new zero-day vulnerabilities to silently install malware on Firefox and Windows devices across Europe and North America. Both Mozilla and Microsoft have now released patches for the exploited flaws.

Security researchers discover that RomCom, a Russian-linked hacking group, actively exploits two previously unknown zero-day vulnerabilities targeting Firefox and Windows users. The hackers combine these flaws to create a sophisticated "zero-click" exploit that remotely installs malware without requiring any interaction from the victim.

To trigger the attack, targets simply visit a malicious website controlled by the hacking group, which then installs RomCom's backdoor malware on the victim's computer. This widespread campaign primarily affects users in Europe and North America, with the number of potential victims in each country ranging from one to as many as 250 individuals.

Software makers respond quickly to the threat, with Mozilla patching the Firefox vulnerability on October 9 after receiving an alert from ESET researchers. Microsoft addresses the Windows flaw on November 12 following a report from Google's Threat Analysis Group, which suggests the exploit may be used in other government-backed hacking campaigns.

Read More at the original source →