logo

Nuclear Exploit Kit - Complete Infection Cycle

ID: 3a8ae398-90f1-5aa6-8301-610661336db8

STIX ID: report--3a8ae398-90f1-5aa6-8301-610661336db8

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ observed a surge in Nuclear Exploit Kit activity where compromised legitimate websites redirect victims through a chain to an obfuscated EK landing page; the EK uses PluginDetect-based fingerprinting to target vulnerable browser plugins (Flash, Silverlight, PDF/Reader) and serves exploits (e.g., CVE-2013-0074, CVE-2014-0515) that drop a malware payload with low antivirus detection — the report includes URLs, IPs, and MD5 hashes as indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.