logo

Rise In Red Kit Exploit Kit Activity

ID: 135fe049-a7c8-5bbe-b2a0-298fd46fef50

STIX ID: report--135fe049-a7c8-5bbe-b2a0-298fd46fef50

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes a live campaign in which compromised websites (examples: neptunebenson.com, route66marathon.com, whitesteeple.com) redirect visitors to a RedKit exploit kit via iframe injections and SEO-driven HTTP 302 redirects. The kit uses a Java unsigned applet to exploit several CVEs, fetch an AES-encrypted UPX-packed payload, decrypt and drop a keylogger/infostealer that exfiltrates credentials; detection is low and the report includes sample URLs and technical details for analysis and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.