HomeSecurityCapesand: New exploit kit that exploits vulnerabilities in Adobe Flash and Internet...

Capesand: New exploit kit exploits vulnerabilities in Adobe Flash and Internet Explorer

CapesandIn October, researchers at TrendMicro discovered a new exploit kit, which they named Capesand. The exploit kit is already being used in attacks, despite still being in development.

Researchers discovered the tool while examining a malvertising campaign that used RIG EK to infect victims' systems with DarkRAT and njRAT.

Analysis showed that the Capesand exploit kit code is quite simple.

Capesand exploits recent vulnerabilities in Adobe Flash and Internet Explorer (IE) as well as an vulnerability from 2015. Researchers noted that the kit is still in development.

“In mid-October, we discovered a malvertising campaign that used the Rig exploit kit and distributed the DarkRAT and njRAT malware. Towards the end of October, however, we noticed a change in the campaign and the redirect no longer led to the Rig exploit kit,” Trend Micro said. “The criminals started using another kit that we were not familiar with.”

Capesand: New exploit kit exploits vulnerabilities in Adobe Flash and Internet Explorer

The malvertising campaign appeared as a blog talking about blockchain.

Researchers analyzed the page's source code and discovered that the hackers had copied its content using the website copying tool, HTTrack, and had placed a hidden iframe that loads the exploit kit.

“In the case we identified, we found that it resembles a very old exploit kit called Demon Hunter, which led us to believe that Capesand likely originated from it,” the analysis continues.

What vulnerabilities does Capesand EK exploit?

  • CVE-2018-4878 (Adobe Flash)
  • CVE-2018-8174 (Internet Explorer)
  • CVE-2019-0752 (Internet Explorer)

Another interesting feature that the researchers noticed is that the exploits are not included in the frontend EK source code package. Capesand delivers a specific exploit code by making a request to an API server.

Researchers also discovered a version of Capesand that uses exploits for the following vulnerabilities:

  • CVE-2018-4878 (Adobe Flash)
  • CVE-2018-15982 (Adobe Flash)
  • CVE-2015-2419 (Internet Explorer)
  • CVE-2018-8174 (Internet Explorer)

In addition to the above, criminals distribute malicious pages through “mirrored versions” of legitimate sites and use domain names that closely resemble the originals. This way they avoid detection.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS