logo

An Update On Nuclear (Reverse) Engineering

ID: fc819b99-ee24-597d-8fbb-a3f73e345374

STIX ID: report--fc819b99-ee24-597d-8fbb-a3f73e345374

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This analysis details a Nuclear exploit-kit campaign that compromises WordPress sites to serve obfuscated landing pages which probe browser/Flash versions and exploit CVE-2015-5122, CVE-2015-5560 (Flash) and CVE-2014-6332 (IE). Post-exploitation payloads observed include the Fareit infostealer and Troldesh ransomware; the report documents TTPs (iframe injection, obfuscation, DH/XTEA protections), C2-evasion techniques including Tor and blend-in HTTP POSTs, and specific IOCs such as [email protected], [email protected] and a4yhexpmth2ldj3v.onion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.