logo

Malvertising Campaign Leading To Zemot

ID: 5eb2ec7e-f832-5523-9e90-b03f5fb0d628

STIX ID: report--5eb2ec7e-f832-5523-9e90-b03f5fb0d628

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A widespread malvertising campaign abuses Zedo ad placements to redirect victims through obfuscated domains to a Swedish geobalancer and ultimately to a site serving the Nuclear Exploit Kit, which drops a Zemot payload via a Kuluoz variant. Zscaler observed multiple legitimate sites compromised and reports an IOC of a temporary batch file (e.g., C:\Users\WIN7\AppData\Local\Temp\tmp37cd8110.bat).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.