logo

Exploit Kit still sharpens a sword

ID: 9b9a2ba5-ced2-5695-b6a3-48a2e47b5725

STIX ID: report--9b9a2ba5-ced2-5695-b6a3-48a2e47b5725

Feed Name: Nao_Sec

Threat Score

Date Published: 2021-04-15

Date Updated: 2026-03-24

Author: nao_sec

...
...

This report outlines the continued prevalence of drive-by download attacks in April 2021 despite the decline of Internet Explorer, profiling six active exploit kits (RIG, Spelevo, PurpleFox, Underminer, Bottle, Magnitude) that are leveraging recent and older vulnerabilities—especially CVE-2021-26411—to deliver malware such as PurpleFox, Hidden Bee, and Cinobi. It highlights geographic targeting (e.g., Japan, South Korea, Taiwan), the private/public status of kits, and their update cadence, concluding with the recommendation to stop using Internet Explorer to mitigate these threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.