CVE-2015-5119
published 2015-07-08CVE-2015-5119: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
99.34%
99.9th percentile
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | flash_player | <= 11.2.202.468 | — |
| adobe | flash_player | 13.0.0.182 – 13.0.0296 | — |
| adobe | flash_player | 14.0.0.125 – 18.0.0.194 | — |
| opensuse | evergreen | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_from_rhui | — | — |
| redhat | enterprise_linux_server_from_rhui | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_workstation_extension | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2015-5119 is a Use-After-Free in Adobe Flash Player's ByteArray class (AS3), triggered when crafted Flash content overrides a valueOf function — look for SWF files exploiting ByteArray valueOf overrides. ↗
- →CVE-2015-5119 was rapidly integrated into Angler, Nuclear, Neutrino, and Fiddler exploit kits — network traffic associated with these EKs should be inspected for Flash exploit delivery. ↗
- →A Flash exploit based on CVE-2015-5119 was integrated into Angler EK within hours of the Hacking Team data dump — treat any Angler EK traffic from July 2015 onward as potentially carrying this exploit. ↗
- →The exploit targets Flash Player via major browsers (Chrome, Firefox, IE, Safari) and also via embedded SWF in Microsoft Office documents (2007/2010/2013) — monitor for Office documents with embedded SWF content. ↗
- →The Underminer exploit kit uses cookie detection to prevent repeated exploit site visits — monitor for unusual cookie-setting behavior combined with Flash Player version profiling in HTTP traffic. ↗
- →The Underminer exploit kit (which uses CVE-2015-5119) encrypts traffic with RSA prior to exploitation — look for encrypted non-standard traffic patterns preceding Flash exploit delivery. ↗
- →The exploit was confirmed working on Windows XP and Windows 7 with the latest Flash 18 at the time; also supported OS X targeting — prioritize detection on these platforms. ↗
- →The Chrome sandbox could be bypassed by chaining CVE-2015-5119 with an unpatched Windows kernel privilege escalation vulnerability — look for Flash exploit followed by kernel-level privilege escalation activity. ↗
- →Tenable Plugin IDs 84641, 84642, 84667, and 84645 detect vulnerable Adobe Flash/AIR/Chrome versions affected by CVE-2015-5119 — use these for vulnerability scanning. ↗
- ·The two MD5 hashes (31d03169b9742a0ff04e3d24bb448bbf and fcecd6b624bb50301a17d5aa423e135d) are noted in the Zscaler post under CVE-2015-5122 (valueOf UAF in TextBox), not CVE-2015-5119 — verify before using as CVE-2015-5119 indicators. ↗
- ·The SHA-256 hash from Tenable/VirusTotal (a795deaa...) is associated with the Underminer exploit kit payload (Hidden Mellifera coin miner), not exclusively CVE-2015-5119 — confirm the specific exploit used before attributing. ↗
- ·The patched version of Flash Player is 18.0.0.203 for Windows and Mac — ensure detections distinguish between vulnerable (≤18.0.0.194) and patched versions. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Flash Player up to 11.2.202.468/13.0.0.296/18.0.0.194 ActionScript 3 ValueOf memory corruption (apsb15-16 / VU#561288)
vuldb·2026-04-22·CVSS 9.8
CVE-2015-5119 [CRITICAL] Adobe Flash Player up to 11.2.202.468/13.0.0.296/18.0.0.194 ActionScript 3 ValueOf memory corruption (apsb15-16 / VU#561288)
A vulnerability marked as critical has been reported in Adobe Flash Player up to 11.2.202.468/13.0.0.296/18.0.0.194. Affected is the function ValueOf of the component ActionScript 3. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2015-5119. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. This vulnerability is considered historic because of its background and reception.
A worm is propagating and is automatically exploiting this vulnerability.
It is suggested to upgrade the affected component.
GHSA
GHSA-3792-ff84-674w: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13
ghsa_unreviewed·2022-05-17
CVE-2015-5119 [HIGH] CWE-119 GHSA-3792-ff84-674w: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Project0
Attacking ECMAScript Engines with Redefinition - Project Zero
project_zero·2015-08-01·CVSS 9.3
CVE-2013-0765 [CRITICAL] Attacking ECMAScript Engines with Redefinition - Project Zero
Posted by Natalie Silvanovich = function () { return n; }
ECMAScript has a property where almost all functions and variables can be dynamically redefined. This can lead to vulnerabilities in situations where native code assumes a function or variable behaves a certain way when accessed or does not have certain side effects when it can in fact be redefined. Project Zero has discovered 24 vulnerabilities involving ECMAScript redefinition in Adobe Flash in the past few months and similar issues have also been discovered in the wild. This post describes how this class of bugs works, alongside some examples of interesting bugs that have been recently patched.
ECMAScript Redefinition
Being a dynamically typed language, ECMAScript allows all functions to be redefined. For example, the JavaSc
OSV
CVE-2015-5119: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13
osv·2015-07-08·CVSS 9.8
CVE-2015-5119 [CRITICAL] CVE-2015-5119: Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
VulnCheck
Adobe Flash Player Use-After-Free Vulnerability
vulncheck·2015·CVSS 9.8
CVE-2015-5119 [CRITICAL] CWE-119 Adobe Flash Player Use-After-Free Vulnerability
Adobe Flash Player Use-After-Free Vulnerability
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
Affected: Adobe Flash Player
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cve.org/CVERecord?id=CVE-2015-5119; https://resources.infosecinstitute.com/topic/the-hacking-team-hack-when-hackers-have-become-the-target/; https://www.trendmicro.com/en_us/research/15/g/hacking-team-leak-uncovers-another-windows-zero-day-ms-releases-patch.html; https://paper.seebug.org/papers/A
CISA
Adobe Flash Player Use-After-Free Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2015-5119 [CRITICAL] CWE-119 Adobe Flash Player Use-After-Free Vulnerability
Vulnerability: Adobe Flash Player Use-After-Free Vulnerability
Affected: Adobe Flash Player
A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an attacker to perform remote code execution.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-5119
Remediation Due Date: 2022-03-24
Red Hat
flash-plugin: code execution issue in APSA15-03 / APSB15-16
vendor_redhat·2015-07-07·CVSS 9.8
CVE-2015-5119 [CRITICAL] CWE-416 flash-plugin: code execution issue in APSA15-03 / APSB15-16
flash-plugin: code execution issue in APSA15-03 / APSB15-16
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
Exploit-DB
Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
exploitdb·2015-07-08
CVE-2015-5119 Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Adobe Flash Player ByteArray Use After Free',
'Description' => %q{
This module exploits an use after free on Adobe Flash Player. The vulnerability,
discovered by Hacking Team and made public on its July 2015 data leak, was
described as an Use After Free while handling ByteArray objects. This module has
been tested successfully on:
Windows XP, Chrome 43 and Adobe Flash 18.0.0.194,
Windows 7 SP1 (32-bit), IE11 and Adobe Flash 18.0.0.194,
Windows 7 SP1 (32-bit), Firefox 38.0.5 and Adobe Flash 18.0.0.194,
Windows 8.1 (32-bit), Firefox and Adobe Flash 18.0
Metasploit
Adobe Flash Player ByteArray Use After Free
metasploit
Adobe Flash Player ByteArray Use After Free
Adobe Flash Player ByteArray Use After Free
This module exploits an use after free on Adobe Flash Player. The vulnerability, discovered by Hacking Team and made public as part of the July 2015 data leak, was described as an Use After Free while handling ByteArray objects. This module has been tested successfully on: Windows 7 SP1 (32-bit), IE11 and Adobe Flash 18.0.0.194, Windows 7 SP1 (32-bit), Firefox 38.0.5 and Adobe Flash 18.0.0.194, Windows 8.1 (32-bit), IE11 and Adobe Flash 18.0.0.194, Windows 8.1 (32-bit), Firefox and Adobe Flash 18.0.0.194, and Linux Mint "Rebecca" (32 bits), Firefox 33.0 and Adobe Flash 11.2.202.468.
Bugzilla
CVE-2015-5122 CVE-2015-5123 flash-plugin: two code execution issues in APSA15-04 / APSB15-18
bugzilla·2015-07-12·CVSS 9.8
CVE-2015-5122 [CRITICAL] CVE-2015-5122 CVE-2015-5123 flash-plugin: two code execution issues in APSA15-04 / APSB15-18
CVE-2015-5122 CVE-2015-5123 flash-plugin: two code execution issues in APSA15-04 / APSB15-18
Adobe Security Advisory APSA15-04 for Adobe Flash Player documents two flaws that can possibly lead to arbitrary code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSA15-04:
Critical vulnerabilities (CVE-2015-5122, CVE-2015-5123) have been identified in Adobe Flash Player 18.0.0.204 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of reports that exploits targeting these vulnerabilities have been published publicly. Adobe expects to make updates available during the week of July 12, 2015.
https://helpx.adobe.com
Bugzilla
flash-plugin: multiple code execution issues fixed in APSB15-16
bugzilla·2015-07-08·CVSS 10.0
CVE-2015-3135 [CRITICAL] flash-plugin: multiple code execution issues fixed in APSB15-16
flash-plugin: multiple code execution issues fixed in APSB15-16
Adobe Security Bulletin APSB15-16 for Adobe Flash Player describes multiple flaws that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSB15-16:
These updates resolve heap buffer overflow vulnerabilities that could lead to code execution (CVE-2015-3135, CVE-2015-4432, CVE-2015-5118).
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, CVE-2015-3134, CVE-2015-4431).
These updates resolve type confusion vulnerabilities that could lead to code execution (CVE-2015-3119, CVE-2015-3120, CVE-2015-3121, CVE-2015-3122, CVE-2015-4433).
These updates resolve use-aft
Bugzilla
CVE-2015-5119 flash-plugin: code execution issue in APSA15-03 / APSB15-16
bugzilla·2015-07-07·CVSS 9.8
CVE-2015-5119 [CRITICAL] CVE-2015-5119 flash-plugin: code execution issue in APSA15-03 / APSB15-16
CVE-2015-5119 flash-plugin: code execution issue in APSA15-03 / APSB15-16
Adobe Security Advisory APSA15-03 for Adobe Flash Player documents a flaw that can possibly lead to code execution when Flash Player is used to play a specially crafted SWF file.
Quoting from the APSA15-03:
A critical vulnerability (CVE-2015-5119) has been identified in Adobe Flash Player 18.0.0.194 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially allow an attacker to take control of the affected system.
Adobe is aware of reports that an exploit targeting this vulnerability has been published publicly. Adobe expects to make updates available on July 8, 2015.
https://helpx.adobe.com/security/products/flash-player/apsa15-03.html
Discussion:
Accord
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
An overview of targeted attacks and APTs on Linux
blogs_securelist·2020-09-10
An overview of targeted attacks and APTs on Linux
Authors
- GReAT
Perhaps unsurprisingly, a lot has been written about targeted attacks on Windows systems. Windows is, due to its popularity, the platform for which we discover most APT attack tools. At the same time, there’s a widely held opinion that Linux is a secure-by-default operating system that isn’t susceptible to malicious code. It’s certainly true that Linux hasn’t faced the deluge of viruses, worms and Trojans faced by those running Windows systems over the years. However, there is certainly malware for Linux – including PHP backdoors, rootkits and exploit code. Moreover, numbers can be misleading. The strategic importance of servers running Linux makes them an attractive target for attackers of all kinds. If an attacker is able to compromise a server running Linux, they not o
Securelist
An overview of targeted attacks and APTs on Linux
blogs_securelist·2020-09-10
An overview of targeted attacks and APTs on Linux
Authors
GReAT
Perhaps unsurprisingly, a lot has been written about targeted attacks on Windows systems. Windows is, due to its popularity, the platform for which we discover most APT attack tools. At the same time, there’s a widely held opinion that Linux is a secure-by-default operating system that isn’t susceptible to malicious code. It’s certainly true that Linux hasn’t faced the deluge of viruses, worms and Trojans faced by those running Windows systems over the years. However, there is certainly malware for Linux – including PHP backdoors, rootkits and exploit code. Moreover, numbers can be misleading. The strategic importance of servers running Linux makes them an attractive target for attackers of all kinds. If an attacker is able to compromise a server running Linux, they not onl
Unit42
Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
blogs_unit42·2018-12-27·CVSS 9.8
[CRITICAL] Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
# Executive Summary
Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
During Quarter 3 (Q3), July – September, a notable shift occurred with the malicious URL and domain data; there was a significant drop in the number of malicious URLs as well as a drop in malicious domains that will be discussed below. In addition, we will be covering an interesting malicious Flash SWF that exploits CVE-2015-5119.
# URLs
Based on our analysis of dat
Unit42
Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
blogs_unit42·2018-12-27·CVSS 9.8
CVE-2015-5119 [CRITICAL] Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
Threat Research Center
Trend Reports
Malware
## Web-based Threats-2018 Q3: Malicious URLs and Domains take a Dip
Bo Qu
Tao Yan
Rongbo Shao
Zhanglin He
Xingyu Jin
Published: December 27, 2018
Malware
Trend Reports
Vulnerabilities
CVE-2015-5119
ELink
## Executive Summary
Our Email Link Analysis (ELINK) system is routinely reviewed by our Unit 42 research team. In examining the data it collects, patterns and trends are discovered which helps us discern prevalent web threats. This blog is the third (3rd quarter of 2018) in a series of posts tracking web-based threats throughout the year, specifically statistics pertaining to malicious URLs, domains, exploit kits, and CVEs.
During Quarter 3 (Q3), July – September, a notable shift occurred with the malicious URL and domain d
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
Blog / Cyber Exposure Alerts
Subscribe
# Underminer Exploit Kit: How Tenable Can Help
Tenable Research
July 31, 2018
2 Min Read
The “Underminer” exploit kit is having widespread impact in Asian countries, particularly Japan. Thankfully, mitigation is relatively simple and involves patching and other well-known security best practices.
Contrary to popular belief, the exploit kit is not dead yet. “Underminer,” an exploit kit named and discovered by Trend Micro, is having widespread impact in Asian countries, particularly Japan. Its nefarious bootkit affects the system’s boot sectors and delivers the coin mining payload named Hidden Mellifera.
While the continued decline of Adobe Flash has led to a reduction in the prevalence of Exploit Kits, enterprises need to remember this attack ve
Trendmicro
Bootkit, Miner Delivered by New Underminer Exploit Kit
blogs_trendmicro·2018-07-26
Bootkit, Miner Delivered by New Underminer Exploit Kit
Cyber Threats
# Bootkit, Miner Delivered by New Underminer Exploit Kit
The newly discovered Underminer exploit kit delivers a bootkit that infects the system’s boot sectors as well as a cryptocurrency-mining malware named Hidden Mellifera.
By: Jaromir Horejsi, Joseph C Chen, Chaoying Liu
2018/07/26
Read time: ( words)
Save to Folio
Updated as of July 27, 2018, 2:08 AM, PDT to include a report about Underminer in November 2017.
Updated as of July 26, 2018, 11:02 PM, PDT to include an updated visualization for Figure 1.
We discovered a new exploit kit we named Underminer that employs capabilities used by other exploit kits to deter researchers from tracking its activity or reverse engineering the payloads. Underminer delivers a bootkit that infects the system’s boot sectors as well a
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
- Introduction
- BlackOasis Background
- Attacks Leveraging CVE-2017-11292
- Targeting and Victims
- Conclusions
- Acknowledgements
- References
- Indicators of compromise
Authors
- GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft Offic
Securelist
BlackOasis APT and new targeted attacks leveraging zero-day exploit
blogs_securelist·2017-10-16·CVSS 9.8
CVE-2017-11292 [CRITICAL] BlackOasis APT and new targeted attacks leveraging zero-day exploit
Table of Contents
Introduction
BlackOasis Background
Attacks Leveraging CVE-2017-11292
Payload – mo.exe
Targeting and Victims
Conclusions
Acknowledgements
References
Indicators of compromise
Authors
GReAT
More information about BlackOasis APT is available to customers of Kaspersky Intelligence Reporting Service. Contact: [email protected]
## Introduction
Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.
On October 10, 2017, Kaspersky Lab’s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft
Securelist
APT Trends report Q2 2017
blogs_securelist·2017-08-08
APT Trends report Q2 2017
Table of Contents
- Introduction
- Russian-Speaking Actors
- English-Speaking Actors
- Korean-speaking Actors
- Middle Eastern Actors
- Chinese-Speaking Actors
- Best of the rest
- Predictions
- How to keep yourself protected
Authors
- GReAT
## Introduction
Since 2014, Kaspersky Lab’s Global Research and Analysis Team (GReAT) has been providing threat intelligence reports to a wide-range of customers worldwide, leading to the delivery of a full and dedicated private reporting service. Prior to the new service offering, GReAT published research online for the general public in an effort to help combat the ever-increasing threat from nation-state and other advanced actors. Since we began offering a threat intelligence service, all deep technical details on advanced campaigns are first
Securelist
APT Trends report Q2 2017
blogs_securelist·2017-08-08·CVSS 7.8
[HIGH] APT Trends report Q2 2017
Table of Contents
Introduction
Russian-Speaking Actors
English-Speaking Actors
Korean-speaking Actors
Middle Eastern Actors
Chinese-Speaking Actors
Best of the rest
Predictions
How to keep yourself protected
Authors
GReAT
## Introduction
Kaspersky’s Private Threat Intelligence Portal (TIP)
In Q1 of 2017 we published our first APT Trends report , highlighting our top research findings over the last few months. We will continue to publish quarterly reports as a representative snapshot of what has been offered in greater detail in our private reports in order to highlight significant events and findings we feel most users should be aware of. If you would like to learn more about our intelligence reports or request more information for a specific report, readers are encouraged to
Checkpoint
2017-6-26 Global Cyber Attack Reports
blogs_checkpoint·2017-06-26
CVE-2017-8558 2017-6-26 Global Cyber Attack Reports
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2017-6-26 Global Cyber Attack Reports
TOP ATTACKS AND BREACHES
Honda, the Japanese motor conglomerate, has halted its car production in one of its domestic car plants, after finding WannaCry ransomware in its network. The affected plant produces approximately 1,000 vehicles a day. It is unknown how and when Honda’s network got infected. In a related topic, WannaCry has hit 55 speed and red-light cameras in Australia, after a human operator has connected an infected USB device to the cameras, which apparently run
Trendmicro
The Trail of BlackTech’s Cyber Espionage Campaigns
blogs_trendmicro·2017-06-22·CVSS 9.8
[CRITICAL] The Trail of BlackTech’s Cyber Espionage Campaigns
# The Trail of BlackTech’s Cyber Espionage Campaigns
Following the activities and evolving tactics of cyberespionage group BlackTech helped us uncover the proverbial red string of fate that connected three seemingly disparate campaigns: PLEAD, Shrouded Crossbow, and of late, Waterbear.
By: Lenart Bermejo, Razor Huang, CH Lei
2017/06/22
Read time: ( words)
Save to Folio
BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes and domain names of some of their C&C servers, BlackTech’s campaigns are likely designed to steal their target’s technology.
Following their activities and evolving tactics and techniques helped us uncover the proverbial red string of fate that connected three see
Unit42
Understanding Angler Exploit Kit - Part 2: Examining Angler EK
blogs_unit42·2016-06-07·CVSS 9.8
[CRITICAL] Understanding Angler Exploit Kit - Part 2: Examining Angler EK
This is the second part of a two-part blog post for understanding Angler exploit kit (EK). The first part covered EKs in general. This blog focuses on the Angler EK.
Angler is currently one of the most advanced, effective, and popular exploit kits in the cyber criminal market. It generally uses the most recent exploits based on the latest vulnerabilities. Like most leading EKs, the authors behind Angler use Software as a Service (SaaS) as their business model, and Angler can be rented in the cyber underground for a few thousand dollars a month.
### History
Angler EK was discovered in 2013, and it began appearing more frequently later that year. Angler grew in popularity sometime after Russian authorities arrested malware kingpin "Paunch", the alleged creator and distributor of Blackhole
Unit42
Understanding Angler Exploit Kit - Part 2: Examining Angler EK
blogs_unit42·2016-06-07
Understanding Angler Exploit Kit - Part 2: Examining Angler EK
Threat Research Center
Threat Research
Ransomware
## Understanding Angler Exploit Kit - Part 2: Examining Angler EK
Brad Duncan
Published: June 7, 2016
Malware
Ransomware
Threat Research
Angler Exploit Kit
CryptXXX
SaaS
This is the second part of a two-part blog post for understanding Angler exploit kit (EK). The first part covered EKs in general. This blog focuses on the Angler EK.
Angler is currently one of the most advanced, effective, and popular exploit kits in the cyber criminal market. It generally uses the most recent exploits based on the latest vulnerabilities. Like most leading EKs, the authors behind Angler use Software as a Service (SaaS) as their business model, and Angler can be rented in the cyber underground for a few thousand dollars a month .
## History
Talos
Rigging compromise - RIG Exploit Kit
blogs_talos·2016-01-07
Rigging compromise - RIG Exploit Kit
This post was authored by Nick Biasini with contributions by Joel Esler.
Exploit Kits are one of the biggest threats that affects users, both inside and outside the enterprise, as it indiscriminately compromises simply by visiting a web site, delivering a malicious payload. One of the challenges with exploit kits is at any given time there are numerous kits active on the Internet. RIG is one of these exploit kits that is always around delivering malicious payloads to unsuspecting users. RIG first appeared in our telemetry back in November of 2013, back then we referred to it as Goon, today it's known as RIG.
We started focusing on RIG and found some interesting data similar to what we found while analyzing Angler. This post will discuss RIG, findings in the data, and what actions were ta
Zscaler
Adobe Flash Vulnerability CVE-2015-5119 Analysis | Zscaler
blogs_zscaler·2015-07-13·CVSS 9.8
[CRITICAL] Adobe Flash Vulnerability CVE-2015-5119 Analysis | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
APT Group UPS Targets US Government with Hacking Team Flash Exploit
blogs_unit42·2015-07-10·CVSS 9.8
[CRITICAL] APT Group UPS Targets US Government with Hacking Team Flash Exploit
On July 8, 2015, Unit 42 used the AutoFocus Threat Intelligence service to locate and investigate activity consistent with a spear-phishing attack targeting the US Government. The attack exploited an Adobe Flash vulnerability that stems from the zero-day vulnerabilities exposed from this month’s Hacking Team data breach.
The spear-phishing attack used a link to a Flash exploit hosted on two subdomains of a legitimate website, perrydale[.]com; rpt.perrydale[.]com and report.perrydale[.]com. Both domains resolve to the same Ukraine-based IP 194.44.130.179.
There are no indications at this time that the actual website has been compromised, rather, this is more likely a case of DNS hijacking. The Flash exploits, specifically located at rpt.perrydale[.]com/en/show.swf and report.perrydale[.]c
Unit42
APT Group UPS Targets US Government with Hacking Team Flash Exploit
blogs_unit42·2015-07-10·CVSS 9.8
[CRITICAL] APT Group UPS Targets US Government with Hacking Team Flash Exploit
Threat Research Center
Threat Research
Malware
## APT Group UPS Targets US Government with Hacking Team Flash Exploit
Bryan Lee
Robert Falcone
Published: July 10, 2015
Malware
Threat Research
ActionScript
Adobe Flash
Hacking Team
On July 8, 2015, Unit 42 used the AutoFocus Threat Intelligence service to locate and investigate activity consistent with a spear-phishing attack targeting the US Government. The attack exploited an Adobe Flash vulnerability that stems from the zero-day vulnerabilities exposed from this month’s Hacking Team data breach.
The spear-phishing attack used a link to a Flash exploit hosted on two subdomains of a legitimate website, perrydale[.]com; rpt.perrydale[.]com and report.perrydale[.]com. Both domains resolve to the same Ukraine-based IP 194.44.130
Zscaler
Hacking Team Leak, Flash 0day, Exploit Payloads | Zscaler
blogs_zscaler·2015-07-08·CVSS 9.8
[CRITICAL] Hacking Team Leak, Flash 0day, Exploit Payloads | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Volexity
APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)
blogs_volexity·2015-07-08·CVSS 9.8
CVE-2015-5119 [CRITICAL] APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)
Threat Intelligence
# APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)
July 8, 2015
Volexity
As if the recent breach and subsequent public data dump involving the Italian company Hacking Team wasn’t bad enough, it all gets just a little bit worse. Emerging from the bowels of Hacking Team data dump was a Flash 0-day exploit (CVE-2015-5119) that was just patched today by Adobe as covered in APSB15-16. The exploit has since been added into the Angler Exploit Kit and integrated into Metasploit. However, not to be out done, APT attackers have also started leveraging the exploit in targeted spear phishing attacks as well. Before we start dishing the details, there is going to be one main takeaway from this blog post: If you haven’t already, update/patch your Adobe Flash now.
#
Volexity
APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)
blogs_volexity·2015-07-08·CVSS 9.8
CVE-2015-5119 [CRITICAL] APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)
Threat Intelligence
## APT Group Wekby Leveraging Adobe Flash Exploit (CVE-2015-5119)
July 8, 2015
Volexity
As if the recent breach and subsequent public data dump involving the Italian company Hacking Team wasn’t bad enough, it all gets just a little bit worse. Emerging from the bowels of Hacking Team data dump was a Flash 0-day exploit (CVE-2015-5119) that was just patched today by Adobe as covered in APSB15-16 . The exploit has since been added into the Angler Exploit Kit and integrated into Metasploit . However, not to be out done, APT attackers have also started leveraging the exploit in targeted spear phishing attacks as well. Before we start dishing the details, there is going to be one main takeaway from this blog post: If you haven’t already, update/patch your Adobe Flash now
Krebs
Adobe to Patch Hacking Team’s Flash Zero-Day
blogs_krebs·2015-07-07·CVSS 9.8
[CRITICAL] Adobe to Patch Hacking Team’s Flash Zero-Day
Adobe Systems Inc. says its plans to issue a patch on Wednesday to fix a zero-day vulnerability in its Flash Player software that is reportedly being exploited in active attacks. The flaw was disclosed publicly over the weekend after hackers broke into and posted online hundreds of gigabytes of data from Hacking Team, a controversial Italian company that’s long been accused of helping repressive regimes spy on dissident groups.
A knowledge base file stolen from Hacking Team explaining how to use a Flash exploit developed by the company.
In an advisory published today, Adobe said “a critical vulnerability (CVE-2015-5119) has been identified in Adobe Flash Player 18.0.0.194 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially al
Qualys
Update5 - HackingTeam 0-day for Flash | Qualys
blogs_qualys·2015-07-07·CVSS 9.8
CVE-2015-5123 [CRITICAL] Update5 - HackingTeam 0-day for Flash | Qualys
Update5: Adobe has added a second vulnerability to APSA15-04, CVE-2015-5123, which TrendMicro has found. PoC code is available but not integrated into ExploitKits yet.
Update4: Adobe has acknowledged in APSA15-04 another 0-day for Flash originating in the data dump from HackingTeam. Security researcher Webdevil documents his finding in a tweet. Adobe credits Dhanesh Kizhakkian from FireEye who documented the PoC found in the datadump and notified Adobe (first?). Adobe expects to address the vulnerability next week (during normal Patch Tuesday maybe?). According to @Kafeine the vulnerability is already in use in the Angler Exploit Kit.
Update3: Adobe has released the patch for the HackingTeam 0-day, CVE-2015-5119. Beyond that vulnerability the update APSB15-16 also addresses 42 other vuln
Qualys
Update5 - HackingTeam 0-day for Flash | Qualys
blogs_qualys·2015-07-06·CVSS 9.8
CVE-2015-5123 [CRITICAL] Update5 - HackingTeam 0-day for Flash | Qualys
Update5: Adobe has added a second vulnerability to APSA15-04 , CVE-2015-5123, which TrendMicro has found. PoC code is available but not integrated into ExploitKits yet.
Update4: Adobe has acknowledged in APSA15-04 another 0-day for Flash originating in the data dump from HackingTeam. Security researcher Webdevil documents his finding in a tweet . Adobe credits Dhanesh Kizhakkian from FireEye who documented the PoC found in the datadump and notified Adobe (first?). Adobe expects to address the vulnerability next week (during normal Patch Tuesday maybe?). According to @Kafeine the vulnerability is already in use in the Angler Exploit Kit.
Update3: Adobe has released the patch for the HackingTeam 0-day, CVE-2015-5119. Beyond that vulnerability the update APSB15-16 also addresses 42 other vu
Krebs
Adobe to Patch Hacking Team’s Flash Zero-Day – Krebs on Security
blogs_krebs·2015-07-01·CVSS 9.8
[CRITICAL] Adobe to Patch Hacking Team’s Flash Zero-Day – Krebs on Security
Adobe Systems Inc. says its plans to issue a patch on Wednesday to fix a zero-day vulnerability in its Flash Player software that is reportedly being exploited in active attacks. The flaw was disclosed publicly over the weekend after hackers broke into and posted online hundreds of gigabytes of data from Hacking Team , a controversial Italian company that’s long been accused of helping repressive regimes spy on dissident groups.
A knowledge base file stolen from Hacking Team explaining how to use a Flash exploit developed by the company.
In an advisory published today, Adobe said “a critical vulnerability (CVE-2015-5119) has been identified in Adobe Flash Player 18.0.0.194 and earlier versions for Windows, Macintosh and Linux. Successful exploitation could cause a crash and potentially a
Recorded Future
Analyzing Attack Vector Trends by Industry, Country, and More
blogs_recorded_future
Analyzing Attack Vector Trends by Industry, Country, and More
# Analyzing Attack Vector Trends by Industry, Country, and More
Cyber security professionals are flooded with issues requiring their attention. Identifying the most significant risks can be challenging, which makes choosing where to allocate resources even more difficult. This applies to both short term tactical decisions (e.g., Which vulnerabilities do I prioritize this week?) and longer term strategic decisions (e.g., Where do I invest in technology?) for the organization.
Recorded Future provides real-time situational awareness of trending information security topics to support those critical choices. This is done by analyzing millions of documents from the Web daily. The unstructured text from security blogs, threat researchers, mainstream media, and much more is mined and given stru
Crowdstrike
Sakula Malware: What Is the INOCNATION Campaign?
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Sakula Malware: What Is the INOCNATION Campaign?
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016
blogs_recorded_future·CVSS 7.8
[HIGH] New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016
# Gone in a Flash: Top 10 Vulnerabilities Used by Exploit Kits
### Analysis Summary
- Adobe Flash Player provided eight of the top 10 vulnerabilities used by exploit kits in 2015.
- Vulnerabilities in Microsoft’s Internet Explorer and Silverlight are also major targets.
- Angler is currently the most popular exploit kit, regularly tied to malware including Cryptolocker.
- Identifying targeted vulnerabilities can better inform patch management functions within organizations.
- Some security professionals suggest uninstalling Adobe Flash Player. Enabling “Click to Play” is a stop-gap.
Recorded Future threat intelligence analysis of over 100 exploit kits (EKs) and known vulnerabilities identified Adobe Flash Player as the most frequently exploited product. While the role of Adobe Flash vul
Recorded Future
Analyzing Attack Vector Trends by Industry, Country, and More
blogs_recorded_future
Analyzing Attack Vector Trends by Industry, Country, and More
## Analyzing Attack Vector Trends by Industry, Country, and More
Cyber security professionals are flooded with issues requiring their attention. Identifying the most significant risks can be challenging, which makes choosing where to allocate resources even more difficult. This applies to both short term tactical decisions (e.g., Which vulnerabilities do I prioritize this week?) and longer term strategic decisions (e.g., Where do I invest in technology?) for the organization.
Recorded Future provides real-time situational awareness of trending information security topics to support those critical choices. This is done by analyzing millions of documents from the Web daily. The unstructured text from security blogs, threat researchers, mainstream media, and much more is mined and given str
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 07-21-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 07-21-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016 | Recorded Future
blogs_recorded_future·CVSS 7.8
[HIGH] New Kit, Same Player: Top 10 Vulnerabilities Used by Exploit Kits in 2016 | Recorded Future
## Gone in a Flash: Top 10 Vulnerabilities Used by Exploit Kits
## Analysis Summary
Adobe Flash Player provided eight of the top 10 vulnerabilities used by exploit kits in 2015.
Vulnerabilities in Microsoft’s Internet Explorer and Silverlight are also major targets.
Angler is currently the most popular exploit kit, regularly tied to malware including Cryptolocker.
Identifying targeted vulnerabilities can better inform patch management functions within organizations.
Some security professionals suggest uninstalling Adobe Flash Player. Enabling “Click to Play” is a stop-gap.
Recorded Future threat intelligence analysis of over 100 exploit kits (EKs) and known vulnerabilities identified Adobe Flash Player as the most frequently exploited product. While the role of Adobe Flash vulnerabi
Threat Intel
BlackTech (BlackTech, Palmerworm)
threat_intel·CVSS 9.8
[CRITICAL] BlackTech (BlackTech, Palmerworm)
# Threat Actor Profile: BlackTech
ATT&CK ID: G0098
Also known as: BlackTech, Palmerworm
Suspected origin: China
## Overview
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has used a combination of custom malware, dual-use tools, and living off the land tactics to compromise media, construction, engineering, electronics, and financial company networks.(Citation: TrendMicro BlackTech June 2017)(Citation: Symantec Palmerworm Sep 2020)(Citation: Reuters Taiwan BlackTech August 2020)
## Techniques (TTPs)
### Resource Development
- T1588.003 Code Signing Certificates
Usage: BlackTech has used stolen code-signing certificates for its malicious pay
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 07-14-2015
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 07-14-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
Falcon Zero-Day Flash Detection
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Falcon Zero-Day Flash Detection
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends
arxiv_fulltext·2026-01-06
A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends
## Abstract
An advanced persistent threat (APT) refers to
a covert and long-term cyberattack,
typically conducted by state-sponsored actors,
targeting critical sectors and often remaining
undetected for long periods.
In response, collective intelligence
from around the globe collaborates
to identify and trace surreptitious activities,
generating substantial documentation
on APT campaigns publicly available on the web.
While
a multitude of prior works predominantly
focus on specific aspects of APT
cases, such as
detection, evaluation,
cyber threat intelligence, and dataset creation,
limited attention
has been devoted to revisiting and
investigating these scattered
dossiers in a longitudinal manner.
The objective of our study lies
in filling the gap by offering
a macro perspective,
connect
arXiv
CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
arxiv_fulltext·2025-07-12
CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
1
.001
[mode = title]CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis
[1].
[1]Jingwen Li[style=chinese]
Conceptualization, Methodology, Writing–original draft
[1]organization=Beijing University of Posts and Telecommunications,
city=Beijing,
postcode=100876,
country=China
[1]Ru Zhang[style=chinese, orcid=0000-0001-6641-3236]
[1]
[email protected]
Supervision, Writing-Review & Editing
[1]Jianyi Liu[style=chinese]
Methodology, Writing-Review & Editing, Resources
[2]WanGuo Zhao[style=chinese]
Data curation, Resources
[2]organization=Beijing Anheng Xin'an Technology Co., Ltd,
city=Beijing,
postcode=100089,
country=China
[1]Corresponding author
## Abstract
With the increasing complexity of cyberattacks, the proactive and f
arXiv
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
arxiv_fulltext·2025-02-12
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
Almuthanna Alageel
and
Sergio Maffeis
Department of Computing
Imperial College London
London, United Kingdom
plain
plain
## Abstract
The scarcity of data and the high complexity of Advanced Persistent Threats (APTs) attacks have created challenges in comprehending their behavior and hindered the exploration of effective detection techniques.
To create an effective APT detection strategy, it is important to examine the Tactics, Techniques, and Procedures (TTPs) that have been reported by the industry. These TTPs can be difficult to classify as either malicious or legitimate. When developing an approach for the next generation of network intrusion detection systems (NIDS), it is necessary to
http://blog.trendmicro.com/trendlabs-security-intelligence/unpatched-flash-player-flaws-more-pocs-found-in-hacking-team-leak/http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1214.htmlhttp://twitter.com/w3bd3vil/statuses/618168863708962816http://www.kb.cert.org/vuls/id/561288http://www.rapid7.com/db/modules/exploit/multi/browser/adobe_flash_hacking_team_uafhttp://www.securityfocus.com/bid/75568http://www.securitytracker.com/id/1032809http://www.us-cert.gov/ncas/alerts/TA15-195Ahttps://helpx.adobe.com/security/products/flash-player/apsa15-03.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb15-16.htmlhttps://packetstormsecurity.com/files/132600/Adobe-Flash-Player-ByteArray-Use-After-Free.htmlhttps://security.gentoo.org/glsa/201507-13http://blog.trendmicro.com/trendlabs-security-intelligence/unpatched-flash-player-flaws-more-pocs-found-in-hacking-team-leak/http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1214.htmlhttp://twitter.com/w3bd3vil/statuses/618168863708962816http://www.kb.cert.org/vuls/id/561288http://www.rapid7.com/db/modules/exploit/multi/browser/adobe_flash_hacking_team_uafhttp://www.securityfocus.com/bid/75568http://www.securitytracker.com/id/1032809http://www.us-cert.gov/ncas/alerts/TA15-195Ahttps://helpx.adobe.com/security/products/flash-player/apsa15-03.htmlhttps://helpx.adobe.com/security/products/flash-player/apsb15-16.htmlhttps://packetstormsecurity.com/files/132600/Adobe-Flash-Player-ByteArray-Use-After-Free.htmlhttps://security.gentoo.org/glsa/201507-13https://github.com/cisagov/vulnrichment/issues/196https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-5119
2015-07-08
Published
2022-03-03
Added to CISA KEV
Exploited in the wild