logo

APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)

ID: d0781197-de35-51f7-ad22-3ada6dbed342

STIX ID: report--d0781197-de35-51f7-ad22-3ada6dbed342

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2015-07-08

Date Updated: 2026-05-01

...
...

This Volexity report documents a spear-phishing campaign by the Wekby APT that used a Flash 0-day (CVE-2015-5119) from the Hacking Team dump to deliver a modified Gh0st RAT (Rdws.exe). The malicious SWF (movie.swf) drops the RAT into the user Temp folder, establishes persistence via HKCU Run (NAME: CSics), and beacons to C2 223.25.233.248 (associated hostnames gmail.bkz88.com, info.imly.org). The report provides file hashes (movie.swf MD5: 079a440bee0f86d8a59ebc5c4b523a07, Rdws.exe MD5: cfbcb83f8515bd169afd0b22488b4430), a Snort/ET signature for the Gh0st variant, and recommends immediate Adobe Flash patching and mitigations such as EMET.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.