logo

USPS.gov Website Infected with Blackhole EK

ID: ec1156fc-0568-51a1-af68-37c3296100fa

STIX ID: report--ec1156fc-0568-51a1-af68-37c3296100fa

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** A United States Postal Service RIBBS site (ribbs.usps.gov) was compromised and used to deliver the Blackhole exploit kit via an encoded JavaScript iframe and a staged redirect to a malicious page disguised as a 404 error. The attack performs browser and OS fingerprinting to select appropriate exploits and served multiple payloads (EXE, JAR, PDF, PHP) with low antivirus detection rates; the intermediate malicious redirect domain was later taken offline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.