Exploit Kit Activity Roundup Spring 2019
ID: a7717b9a-64f8-52f0-ad52-a2bf6e94c67d
STIX ID: report--a7717b9a-64f8-52f0-ad52-a2bf6e94c67d
Feed Name: Zscaler Security Research Blog
This Zscaler ThreatLabZ quarterly roundup (Mar–May 2019) documents active exploit kit activity — notably RIG, newly observed Underminer and Spelevo — that use malvertising and legacy browser/Flash vulnerabilities (multiple CVEs) to deliver payloads such as SmokeLoader, AZORult, and bootkit malware; it also details router-targeting DNS-hijacking scripts, provides IOCs and infection-chain screenshots, and recommends blocking untrusted third-party scripts and keeping software patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
