logo

Expack Continues Exploiting Java Vulnerability

ID: ab37a295-0810-5b40-9a77-3a38e085ac3c

STIX ID: report--ab37a295-0810-5b40-9a77-3a38e085ac3c

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report examines an exploit kit observed at 174.142.240.91 that exploits CVE-2012-1723 in Java to load an obfuscated applet and download malicious JARs (MD5s provided), leading to a Trojan that communicates with a C2 and retrieves a ZeroAccess-like rootkit (6.exe). The write-up includes IOCs (IP, URLs, MD5 hashes), discusses the exploitation chain and obfuscation, and advises patching or disabling browser Java to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.