RIG Exploit Kit Infection Cycle Analysis
ID: 0bc4a9d8-e536-5d9b-96cb-d0da5a0488c9
STIX ID: report--0bc4a9d8-e536-5d9b-96cb-d0da5a0488c9
Feed Name: Zscaler Security Research Blog
**Executive Summary:** The report analyzes the RIG exploit kit's full infection chain — from malvertising and compromised-site iframes to obfuscated landing pages that execute VBScript and Flash exploits (CVE-2014-6332, CVE-2015-0313) — resulting in an encrypted payload that performs process hollowing and a secondary Blue Botnet .NET payload; the write-up includes technical details, deobfuscation artifacts, network indicators (domains, IPs, URIs), and observed C2 behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
