logo

Ongoing Angler Exploit Kit And Bedep Fraud Campaign

ID: 35fb5f92-4d77-5dfe-bc0c-7ac88507cece

STIX ID: report--35fb5f92-4d77-5dfe-bc0c-7ac88507cece

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes a Bedep malware campaign that leveraged the CVE-2015-0311 Flash exploit to install binaries which resolve DGA-generated domains using regway.com nameservers; researchers enumerated ~70+ malicious domains (many resolving to OVH-hosted IPs), multiple ASNs/netblocks, examples of C2 POSTs with base64 payloads, and use of the infrastructure for click-fraud and Reveton ransomware pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.