Romain Dumont

Romain Dumont

Malware Researcher



10 articles by Romain Dumont

Beware the SparroWock: The backdoor that bites, the commands that catch

Beware the SparroWock: The backdoor that bites, the commands that catch

Beware the SparroWock: The backdoor that bites, the commands that catch

ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group

Alexandre Côté Cyr and Romain Dumont • 17 Sep 2026 • 17 min. read


Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component

Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component

Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component

A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation

Romain Dumont • 22 Dec 2025 • 8 min. read


RomCom exploits Firefox and Windows zero days in the wild

RomCom exploits Firefox and Windows zero days in the wild

RomCom exploits Firefox and Windows zero days in the wild

ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit

Damien Schaeffer and Romain Dumont • 26 Nov 2024 • 13 min. read


Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

ESET Research details the tools and activities of a new China-aligned threat actor, CeranaKeeper, focusing on massive data exfiltration in Southeast Asia

Romain Dumont • 02 Oct 2024 • 11 min. read


Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Demystifying CVE-2024-7262 and CVE-2024-7263

Romain Dumont • 28 Aug 2024 • 14 min. read


HotPage: Story of a signed, vulnerable, ad-injecting driver

HotPage: Story of a signed, vulnerable, ad-injecting driver

HotPage: Story of a signed, vulnerable, ad-injecting driver

A study of a sophisticated Chinese browser injector that leaves more doors open!

Romain Dumont • 18 Jul 2024 • 23 min. read


A dive into Turla PowerShell usage

A dive into Turla PowerShell usage

A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only

Matthieu Faou and Romain Dumont • 29 May 2019 • 12 min. read


OceanLotus: macOS malware update

OceanLotus: macOS malware update

OceanLotus: macOS malware update

Latest ESET research describes the inner workings of a recently found addition to OceanLotus’s toolset for targeting Mac users

Romain Dumont • 09 Apr 2019 • 6 min. read


Fake or Fake: Keeping up with OceanLotus decoys

Fake or Fake: Keeping up with OceanLotus decoys

Fake or Fake: Keeping up with OceanLotus decoys

ESET researchers detail the latest tricks and techniques OceanLotus uses to deliver its backdoor while staying under the radar

Romain Dumont • 20 Mar 2019 • 12 min. read