What is known
RomCom is a hacker group. It carries out cyberattacks ordered in the interests of the Russian government. It was these cybercriminals who infected the systems of Japanese technology giant Casio last month. According to the news reported by Channel 24, citing the WeLiveSecurity broadcast founded by the ESET company, these people are also known for their aggressive attitudes towards organizations affiliated with Ukraine.
Researchers say they’ve found evidence of this RomCom combined the use of two zero-day bugs. These vulnerabilities are given this name because they are unknown before experts discover the fact that these vulnerabilities have been exploited, and developers have zero days to fix them. These vulnerabilities reportedly allow hackers to create “zero-click” exploits that allow access to the victim’s computer without any interaction.
To run the zero-click exploit, RomCom victims will need to visit a malicious site controlled by a hacking group. After this, a RomCom backdoor of the same name was secretly installed on the victim’s computer, giving wide access to the victim’s device.
ESET researchers Damien Schaeffer and Romain Dumont say the number of potential victims of RomCom’s “large-scale” hacking campaign ranges from one victim per country to 250 people, with most of them located in Europe and North America.
- Mozilla has not yet fixed the vulnerability 9 OctoberThe day after ESET experts reported this. The Tor Project, which developed the Tor Browser based on the Firefox codebase, also closed the vulnerability, but Damien Schaeffer said ESET saw no evidence that Tor was used even once in this hacking campaign.
- Fixed a vulnerability affecting Windows 12 November. Security researchers from Google’s Threat Analysis Group, which investigates cyber attacks and state-sponsored threats, reported the bug to Microsoft, suggesting that the exploit could be used in other state-sponsored hacking campaigns.
If you have not yet installed the latest versions of both programs, it is better to do it as soon as possible and not miss any updates, as they often bring not only new features, but also fixes for found vulnerabilities and bugs.
Source: 24 Tv
John Wilkes is a seasoned journalist and author at Div Bracket. He specializes in covering trending news across a wide range of topics, from politics to entertainment and everything in between.