TechCrunch News 2024年11月27日
Russia-linked hackers exploited Firefox and Windows zero-day bugs in ‘widespread’ hacking campaign
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

俄关联黑客组织RomCom利用两个零日漏洞,攻击欧美地区Firefox浏览器用户和Windows设备所有者。该组织制造零点击漏洞远程植入恶意软件,多家公司已进行漏洞修复。

🎯RomCom利用零日漏洞攻击欧美用户

🚀制造零点击漏洞远程植入恶意软件

🔧多家公司对漏洞进行修复

Security researchers have uncovered two previously unknown zero-day vulnerabilities that are being actively exploited by RomCom, a Russian-linked hacking group, to target Firefox browser users and Windows device owners across Europe and North America.

RomCom is a cybercrime group that is known to carry out cyberattacks and other digital intrusions for the Russian government. The group — which was last month linked to a ransomware attack targeting Japanese tech giant Casio — is also known for its aggressive stance against organizations allied with Ukraine, which Russia invaded in 2014.

Researchers with security firm ESET say they found evidence that RomCom combined use of the two zero-day bugs — described as such because the software makers had no time to roll out fixes before they were used to hack people — to create a “zero click” exploit, which allows the hackers to remotely plant malware on a target’s computer without any user interaction.

“This level of sophistication demonstrates the threat actor’s capability and intent to develop stealthy attack methods,” ESET researchers Damien Schaeffer and Romain Dumont said in a blog post on Monday.

RomCom’s targets would have to visit a malicious website controlled by the hacking group in order to trigger the zero-click exploit. Once exploited, RomCom’s eponymous backdoor would be installed on the victim’s computer, allowing broad access to a victim’s device.

Schaeffer told TechCrunch that the number of potential victims from RomCom’s hacking campaign ranged from a single victim per country to as many as 250 victims, with the majority of targets based in Europe and North America.

Mozilla patched the vulnerability in Firefox on October 9, a day after ESET alerted the browser maker. The Tor Project, which develops the Tor Browser based on Firefox’s codebase, also patched the vulnerability; though Schaeffer told TechCrunch that ESET has seen no evidence that the Tor Browser was exploited during this hacking campaign.

Microsoft patched the vulnerability affecting Windows on November 12. Security researchers with Google’s Threat Analysis Group, which investigates government-backed cyberattacks and threats, reported the bug to Microsoft, suggesting that the exploit may have been used in other government-backed hacking campaigns.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

RomCom 零日漏洞 网络攻击 安全修复
相关文章