Observations on the recent Java 0-day exploits in the wild
ID: c18cf535-1188-5ac9-a016-9cda572a5fb7
STIX ID: report--c18cf535-1188-5ac9-a016-9cda572a5fb7
Feed Name: Fox-IT blog
Threat Score
Fox-IT reports a widespread Java 0-day exploitation campaign (targeting Java 7 and related older CVEs) that deployed multiple malware families—including Hermes and several ZeuS variants—via an exploit kit operating as a 'loads' service; the kit used JavaScript/JAR-based exploits, frequently rotated DynDNS domains generated by a keyword-based generator, and delivered geographically tailored payloads, representing a high-risk, actively exploited vulnerability until patched by Oracle.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
