logo

Chinese Govt. Website Compromised, Leads To Angler

ID: 9da454b3-4243-5308-817e-d9b500c480b8

STIX ID: report--9da454b3-4243-5308-817e-d9b500c480b8

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabZ observed a non-targeted compromise of the Chuxiong Archives (www.cxda.gov.cn) that injected obfuscated code redirecting Internet Explorer users to Angler Exploit Kit landing pages. The Angler kit exploited Flash (CVE-2015-7645) to deliver a CryptoWall 3.0 variant (crypt13), with analysis showing updated landing-page/SWF structures, multiple landing domains and a larger set of C2 servers; the site was remediated within 24 hours. The report provides SWF and landing page analysis and indicators of compromise for detection and tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.