Cyber Espionage APT group using Hacking Team’s 0-day Exploit
ID: fb5f9edb-8c74-510f-b67e-744119c5fbcf
STIX ID: report--fb5f9edb-8c74-510f-b67e-744119c5fbcf
Feed Name: Zscaler Security Research Blog
### Executive Summary Zscaler ThreatLabZ observed a Chinese APT leveraging leaked Hacking Team Flash/HTML/JS exploits (CVE-2015-5119) in a spear-phishing campaign against a financial services firm to deploy the HttpBrowser RAT. The report documents the full attack chain—remote HK server hosting exploits, SWF exploit download, a DLL-hijack installer using a signed Symantec binary, persistence via Run registry key, SSL-based C2 (update.hancominc.com:8080 and IP 210.209.89.162), supported RAT commands, and file/registry path IOCs—concluding the activity is espionage-focused and provides detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
