logo

LightsOut EK Targets Energy Sector

ID: 0e7dd580-03e5-5cae-ba62-d5d539cb6d6e

STIX ID: report--0e7dd580-03e5-5cae-ba62-d5d539cb6d6e

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A targeted watering-hole campaign in late February compromised a law firm site related to the energy sector and redirected visitors to the LightsOut exploit kit, which fingerprinted victims (browser/plugins) and attempted to deliver a malicious JAR exploiting CVE-2013-2465; research also links the attack infrastructure (e.g., IP 174.129.210.212, aptguide.3dtour.com) to HAVEX RAT C2 activity, signaling intelligence-gathering APT activity and advising monitoring of transaction logs for the attacker’s identifying user-agent patterns and redirects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.