logo

Nuclear Exploit Pack Getting More Aggresive

ID: c93f0a2d-ebca-5a57-8b36-e842d2ba8f41

STIX ID: report--c93f0a2d-ebca-5a57-8b36-e842d2ba8f41

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report documents a recent surge in activity from the Nuclear Exploit Pack exploit kit: redirects lead to an obfuscated Java payload that exploits CVE-2013-2460 to run a malicious JAR which downloads and executes a variety of malware (Spyeye/Zbot, ransomware, Caphaw, keyloggers, proxy trojans, spam bots). Researchers observed thousands of transactions, identified hosting IPs (primarily in Russia), collected 19 dropped samples with VirusTotal links, and recommend disabling Java to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.