logo

Weak Drive-by Download attack with “Radio Exploit Kit”

ID: e64111f4-55dd-5a04-8e99-9de635f3b711

STIX ID: report--e64111f4-55dd-5a04-8e99-9de635f3b711

Feed Name: Nao_Sec

Threat Score

Date Published: 2019-07-15

Date Updated: 2026-03-24

Author: nao_sec

...
...

Analysis of the Radio Exploit Kit, a low-sophistication drive-by download operation active since 2019-07-11, shows abuse of CVE-2016-0189 to execute PowerShell/VBScript that retrieves unencrypted AZORult payloads from infrastructure including radiobox-online.org, 95.215.207.24, and 45.12.215.157; the report traces versions v1.0–v1.2.x, outlines the redirect and download chain (e.g., image.vbs2, error.jp, /im/1.jpg), and concludes that although less potent than major EKs, it is active, evolving, and merits monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.