logo

Exploit Kit Activity Roundup Spring 2019

ID: a7717b9a-64f8-52f0-ad52-a2bf6e94c67d

STIX ID: report--a7717b9a-64f8-52f0-ad52-a2bf6e94c67d

Feed Name: Zscaler Security Research Blog

Threat Score
68/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ quarterly roundup (Mar–May 2019) documents active exploit kit activity — notably RIG, newly observed Underminer and Spelevo — that use malvertising and legacy browser/Flash vulnerabilities (multiple CVEs) to deliver payloads such as SmokeLoader, AZORult, and bootkit malware; it also details router-targeting DNS-hijacking scripts, provides IOCs and infection-chain screenshots, and recommends blocking untrusted third-party scripts and keeping software patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.