Fallout is an exploit kit (EK) first identified at the end of August 2018. It was first seen as a part of a malvertising campaign affecting users in Japan, Korea, the Middle East, Southern Europe, and others in the Asia Pacific.
Fallout was observed exploiting vulnerabilities CVE-2018-4878 and CVE-2018-8174 and distributing the Gandcrab ransomware to users in the Middle East.
After some gap, the fallout emerges with more exploits pack and more advanced in delivering the malwares. Fallout EK is distributed via malvertising chains (one of them we track under the name HookAds), especially through adult traffic.
The revised Fallout EK boasts several new features, including integration of the most recent Flash Player exploit. Security researchers identified that Fallout is now the second exploit kit to add CVE-2018-15982.
According to the underground advert promoting Fallout EK, “The code obfuscation and landing generation mechanism has been completely redesigned” and the exploit kit now comes with “Increased performance.”
The same underground ad mentions the removal of the Internet Explorer CVE-2018-8373 RCE vulnerability because of its unstable flow rate.
The other payloads now disseminated via Fallout are Smokebot which was seen installing Azorult, Tinynuke+Azorult, Dridex, the ServHelper tunnel variant, and other malware strains not yet identified.
Indicators of Compromise
185.56.233[.]186 HookAds Campaign
51.15.35[.]154 Fallout EK
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.
Brinker, an innovative narrative intelligence platform dedicated to combating disinformation and influence campaigns, has been…
A recent investigation by cybersecurity researchers has uncovered a large-scale malware campaign leveraging the DeepSeek…
A recent malware campaign has been observed targeting the First Ukrainian International Bank (PUMB), utilizing…
A newly discovered malware, dubbed Trojan.Arcanum, is targeting enthusiasts of tarot, astrology, and other esoteric…
A sophisticated phishing campaign orchestrated by a Russian-speaking threat actor has been uncovered, revealing the…
A sophisticated malware campaign has compromised over 1,500 PostgreSQL servers, leveraging fileless techniques to deploy…