Users visiting the Popular Science website have been targeted by a "drive-by download" attack that uses the RIG Exploit Kit (EK) to spread malicious files to their computers.
Cybercriminals managed to insert code into the website that redirects visitors to an online location hosted by the EK.
In this case, security researchers from Websense observed that EK first checks for the presence of protection software on the target system and proceeds with the attack only if it is not detected by the software.
To accomplish this, cybercriminals exploit another vulnerability, this time in the XMLDOM ActiveX control in Windows 8.1 and below, which allows the enumeration of local resources.
Abel Toro from Websense claims that this tactic has started to be incorporated more frequently into such tools and was also evident in the Nuclear Pack and Angler EK exploit kits.
Another peculiarity is that the TDS (traffic distribution system) is not used and the malicious iframe inserted into the Popular Science leads directly to the RIG EK page.
In analyzing the attack, Toro noticed that the exploit kit page was extremely vague. This is a common tactic used by criminals to make the job of security researchers more difficult.

