Since May of 2014, I've been tracking a particular group that uses the Sweet Orange exploit kit to deliver malware. This group also uses obfuscation to make it harder to detect the infection chain of events.
more here.........https://isc.sans.edu/forums/diary/An+Example+of+Evolving+Obfuscation/19403
more here.........https://isc.sans.edu/forums/diary/An+Example+of+Evolving+Obfuscation/19403