logo

Fiesta Exploit Kit: Live Infection

ID: ed027b69-b11c-5270-b93e-75eb04573fc0

STIX ID: report--ed027b69-b11c-5270-b93e-75eb04573fc0

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report details active Fiesta exploit kit campaigns that leveraged compromised websites (e.g., orpi.com, interfacelift.com, soyentrepreneur.com) to redirect victims to EK landing pages which probe for Silverlight/Flash/Java/Reader plugins and exploit known CVEs to deliver payloads (rtu.swf, rtp.xap, ianlar.jar, Ianlar.pdf). Post-exploitation activity observed includes installation of a Zemot click-fraud Trojan and connections to multiple malicious domains and IPs acting as C2 or click-fraud infrastructure; the report provides numerous indicators of compromise and examples of the EK request patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.