logo

Terror Exploit Kit via Malvertising campaign

ID: f1a224af-5e6f-5ec6-898d-fa48960bd9f2

STIX ID: report--f1a224af-5e6f-5ec6-898d-fa48960bd9f2

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Terror Exploit Kit (EK) activity increased in recent malvertising campaigns that redirect users through fake ads to landing pages exploiting CVE-2016-0189 and CVE-2014-6332 and loading protected Flash (SWF) payloads; these chains delivered Smoke Loader downloader payloads. The report includes technical flow diagrams, notes use of SWF protection tools, sample MD5 hashes and malicious domains, and states ongoing monitoring by Zscaler ThreatLabZ.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.