Desk live·
ForensicPost
Nation-state/Espionage/File 24-1126

RomCom Chained Firefox and Windows Zero-Days Into a Zero-Click Backdoor

ESET found a Russia-aligned group pairing CVE-2024-9680 in Firefox, Thunderbird and Tor Browser with CVE-2024-49039 in Windows. Together they needed no user interaction at all.

Constructed geometry · not a chart of case data
JurisdictionNot establishedthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFirefox and Windows users
ActorRomCom
D. Kennedy9 min readConfidence: high2 sources reviewed

ESET reported in November 2024 that the Russia-aligned group tracked as RomCom had chained two zero-day vulnerabilities: CVE-2024-9680, which allowed code execution in the restricted context of Firefox, Thunderbird and the Tor Browser, and CVE-2024-49039 in Windows, which escaped that restriction. Targets were reported in Europe and North America. Mozilla shipped a fix within about 25 hours of the browser flaw being reported on 8 October; Microsoft released its fix on 12 November.

Zero-Click Is The Property That Matters

Chained together the two flaws required no user interaction. Visiting a page was sufficient — no attachment, no macro, no decision by the person at the keyboard.

Almost every intrusion in this database begins with somebody doing something reasonable: opening a document, answering a call, considering a job. This one removes even that, which also removes every control that depends on user judgement.

A Sandbox Is One Half Of A Pair

The browser flaw only ran code inside the sandbox. On its own it was contained, and the Windows flaw is what made it matter.

Severity scored per vulnerability misses this. Two flaws individually rated as manageable combine into remote compromise with no interaction, and no scoring scheme in common use represents the pair.

Twenty-Five Hours

Mozilla’s turnaround on the browser flaw is the fastest vendor response recorded in this file set.

It is worth naming against the Unisoc case in 2026, where researchers could not get the vendor to reply at all. The range between those two is the whole of what coordinated disclosure delivers in practice.

How we reported this

Compiled from ESET’s published research and public reporting, listed below. Attribution to a Russia-aligned group is the researchers’ assessment; we attribute nothing to any state. No victim count has been published. Corrections: corrections@forensicpost.com.

Sources
  1. RomCom exploits Firefox and Windows zero days in the wildESET
  2. Russia-aligned RomCom hackers exploited Firefox and Windows zero-daysThe Record
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary