logo

Top Exploit Kit Activity 2017

ID: 851352d3-a25d-5143-a764-da984eb78f32

STIX ID: report--851352d3-a25d-5143-a764-da984eb78f32

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ roundup details exploit kit activity from March–June 2017: RIG remains the most active EK distributing Cerber ransomware, cryptominers, and Dreambot (with Tor support); Magnitude runs malvertising targeting Taiwan to deliver Cerber; Terror employs fingerprinting and drops miners, loaders (Andromeda, Smoke Loader) and Win32/Tofsee. The report also notes Neutrino's return and declining activity for KaiXin and Sundown, and describes techniques such as browser/Flash fingerprinting, redirect chains, and region-based filtering used to evade defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.