Nuclear Exploit Pack Getting More Aggresive
ID: c93f0a2d-ebca-5a57-8b36-e842d2ba8f41
STIX ID: report--c93f0a2d-ebca-5a57-8b36-e842d2ba8f41
Feed Name: Zscaler Security Research Blog
The report documents a recent surge in activity from the Nuclear Exploit Pack exploit kit: redirects lead to an obfuscated Java payload that exploits CVE-2013-2460 to run a malicious JAR which downloads and executes a variety of malware (Spyeye/Zbot, ransomware, Caphaw, keyloggers, proxy trojans, spam bots). Researchers observed thousands of transactions, identified hosting IPs (primarily in Russia), collected 19 dropped samples with VirusTotal links, and recommend disabling Java to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
