logo

Observations on the recent Java 0-day exploits in the wild

ID: c18cf535-1188-5ac9-a016-9cda572a5fb7

STIX ID: report--c18cf535-1188-5ac9-a016-9cda572a5fb7

Feed Name: Fox-IT blog

Threat Score
88/100

Date Published: 2012-08-30

Date Updated: 2026-04-27

Author: Fox It

...
...

Fox-IT reports a widespread Java 0-day exploitation campaign (targeting Java 7 and related older CVEs) that deployed multiple malware families—including Hermes and several ZeuS variants—via an exploit kit operating as a 'loads' service; the kit used JavaScript/JAR-based exploits, frequently rotated DynDNS domains generated by a keyword-based generator, and delivered geographically tailored payloads, representing a high-risk, actively exploited vulnerability until patched by Oracle.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.