Veterans Targeted In Attack Using IE 10 Zero Day
ID: 1632f64b-4ba5-54cf-8387-cf6305bade5b
STIX ID: report--1632f64b-4ba5-54cf-8387-cf6305bade5b
Feed Name: Security Ledger
Threat Score
FireEye and Symantec reported a targeted watering‑hole attack on vfw.org that used a previously unknown IE10 use‑after‑free zero‑day to bypass ASLR/DEP and deliver a ZxShell backdoor to visitors—apparently aimed at current and former U.S. military personnel. FireEye labeled the campaign “SnowMan,” observed active exploitation on February 11, and linked it to other strategic web compromise campaigns (e.g., Operation DeputyDog, Ephemeral Hydra).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
