Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Threat Spotlight from Cisco on Previously Discussed Exploit Kit: Angler Lurking in the Domain Shadows

$
0
0
Over the last several months Talos researchers have been monitoring a massive exploit kit campaign that is utilizing hijacked registrant accounts to create large amounts of subdomains for both initial redirection and exploitation. This campaign has been largely attributed to Angler Exploit Kit with fileless exploits serving various malicious payloads.

The use of hijacked accounts lead to a larger research project into the use of hijacked registrant accounts. During this research the earliest examples were found from a 2011 campaign with sporadic usage until December 2014. Since December 2014 more than 75% of the subdomain activity has occurred indicating a major shift in approach. This behavior has been covered before which discussed some of the older campaigns as well as the hosting indicators (ASN) of the groups making use of the subdomains.

more here..........http://blogs.cisco.com/security/talos/angler-domain-shadowing

Viewing all articles
Browse latest Browse all 8064

Trending Articles