Security researchers have uncovered two previously unknown zero-day vulnerabilities that are being actively exploited by RomCom, a Russian-linked hacking group, to target Firefox browser users and Windows device owners across Europe and North America.
Researchers with security firm ESET say they found evidence that RomCom combined use of the two zero-day bugs - described as such because the software makers had no time to roll out fixes before they were used to hack people - to create a 'zero click' exploit, which allows the hackers to remotely plant malware on a target's computer without any user interaction.
This level of sophistication demonstrates the threat actor's capability and intent to develop stealthy attack methods, ESET researchers Damien Schaeffer and Romain Dumont said in a blog post on Monday.
The number of potential victims from RomCom's 'widespread' hacking campaign ranged from a single victim per country to as many as 250 victims, with the majority of targets based in Europe and North America.
Collection
[
|
...
]