logo

Malicious JavaScript targets 3 Old Vulnerabilities

ID: 083d36ba-ea8f-5545-afe8-05b8ee09a7d3

STIX ID: report--083d36ba-ea8f-5545-afe8-05b8ee09a7d3

Feed Name: Zscaler Security Research Blog

Threat Score
45/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report demonstrates a PDF exploitation technique where attackers split malicious JavaScript across objects and encode each part with different filters (ASCIIHexDecode and ASCII85Decode) to evade AV detection; the decoded payload targets three legacy PDF vulnerabilities (CVE-2007-5659, CVE-2008-2992, CVE-2009-0927), a live sample is shown with low antivirus detection rates, and the author recommends defense-in-depth measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.