logo

Neutrino Campaign Leveraging WordPress, Flash For CryptoWall

ID: 962b574f-327f-5295-966b-d505e6102b88

STIX ID: report--962b574f-327f-5295-966b-d505e6102b88

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This ThreatLabZ write-up describes an active Neutrino Exploit Kit campaign that compromises over 2,600 WordPress sites (and >4,200 pages) running version 4.2 and lower to inject iframes which load Neutrino landing pages and a SWF-based exploit chain; successful exploitation downloads and decrypts a binary that beacons and deploys CryptoWall 3.0 ransomware. The report analyzes landing page and SWF structure (including obfuscation and embedded RC4 blobs), notes poor detection rates, provides campaign infrastructure details (e.g., primary IP 185.44.105.7, domains across .xyz/.ga/.gq/.ml, WHOIS samples), and publishes indicators and a domain dump for tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.