logo

Cyber Espionage APT group using Hacking Team’s 0-day Exploit

ID: fb5f9edb-8c74-510f-b67e-744119c5fbcf

STIX ID: report--fb5f9edb-8c74-510f-b67e-744119c5fbcf

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

### Executive Summary Zscaler ThreatLabZ observed a Chinese APT leveraging leaked Hacking Team Flash/HTML/JS exploits (CVE-2015-5119) in a spear-phishing campaign against a financial services firm to deploy the HttpBrowser RAT. The report documents the full attack chain—remote HK server hosting exploits, SWF exploit download, a DLL-hijack installer using a signed Symantec binary, persistence via Run registry key, SSL-based C2 (update.hancominc.com:8080 and IP 210.209.89.162), supported RAT commands, and file/registry path IOCs—concluding the activity is espionage-focused and provides detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.