logo

Say hello to Bottle Exploit Kit targeting Japan

ID: 4cd75da2-f7a8-54b5-b4a4-d8ae951790b8

STIX ID: report--4cd75da2-f7a8-54b5-b4a4-d8ae951790b8

Feed Name: Nao_Sec

Threat Score

Date Published: 2019-12-12

Date Updated: 2026-03-24

Author: nao_sec

...
...

This report documents Bottle Exploit Kit, a malvertising-driven drive-by campaign targeting Japanese users that fingerprints for Japanese-language Internet Explorer and delivers either VBS (CVE-2018-8174) or SWF (CVE-2018-15982) exploits to run shellcode. The payload likely functions as a stealer, downloads auxiliary tools (e.g., unzip, Tor), persists as svchost.exe in %TEMP%, and communicates with onion C2 endpoints. Detailed TTPs and comprehensive IoCs (domains, URLs, file paths, and hashes) are provided to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.