Rise In Red Kit Exploit Kit Activity
ID: 135fe049-a7c8-5bbe-b2a0-298fd46fef50
STIX ID: report--135fe049-a7c8-5bbe-b2a0-298fd46fef50
Feed Name: Zscaler Security Research Blog
This report describes a live campaign in which compromised websites (examples: neptunebenson.com, route66marathon.com, whitesteeple.com) redirect visitors to a RedKit exploit kit via iframe injections and SEO-driven HTTP 302 redirects. The kit uses a Java unsigned applet to exploit several CVEs, fetch an AES-encrypted UPX-packed payload, decrypt and drop a keylogger/infostealer that exfiltrates credentials; detection is low and the report includes sample URLs and technical details for analysis and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
