Hackers now using Rig Exploit Kit to exploiting the Internet Explorer (IE) remote code execution vulnerability ( CVE-2018-8174) with integrating a cryptocurrency-mining malware to mine Monero by Compromising Windows PC.
This vulnerability affected Windows 7 and later versions also this powerful exploit work via Microsoft Office documents and Internet Explorer (IE).
Rig Exploit Kit delivered various payload for many malware and ransomware families such as GandCrab ransomware and Panda Banker. In this case, hackers behind the Rig Exploit Kit employing an exploit for CVE-2018-8174 .
Rig Exploit Kit is capable of Exploit the various vulnerabilities using a vulnerable application such as adobe flash player and IE.
Mainly Rig compromising users by injecting a malicious script/code in compromised websites and redirect the visitors to the exploit kit’s landing page where Rig delivery the Dangerous Malware.
Currently, Rig using Internet Explorer (IE) based remote code execution vulnerability ( CVE-2018-8174) that has been patched in May and reported to be actively exploited.
Researchers Already released a Metasploit module for the exploitation of the CVE-2018-8174 after the PoC code was available online.
Rig Exploit Kit mainly using this exploit against vulnerable Windows VBScript Engine that contains remote code execution vulnerability (CVE-2018-8174 ) using Internet Explorer (IE) and Microsoft Office documents.
This vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user with Rig Exploit Kit.
Initially, Rig using malvertising campaign that contains hidden iframe that redirects victims to Rig’s landing page which is holding an exploit for CVE-2018-8174 and shellcode.
According to Trend Micro research, This enables remote code execution of the shellcode obfuscated in the landing page. After successful exploitation, a second-stage downloader is retrieved, which appears to be a variant of SmokeLoader due to the URL.
Finally, it downloads the Original payload that used to Mine Monero cryptocurrency. Exploit kits can expose victims to multifarious threats — from information theft and file encryption to malicious cryptocurrency mining. Regularly applying the latest patches is an effective defense. Trend Micro said.
Researchers from Duke University and Carnegie Mellon University have demonstrated successful jailbreaks of OpenAI’s o1/o3,…
INE, the leading provider of networking and cybersecurity training and certifications, today announced its recognition…
In a significant cybersecurity revelation, researchers have uncovered a large-scale campaign exploiting a Windows policy…
A sophisticated malware campaign dubbed GitVenom has infected over 200 GitHub repositories, targeting developers with fake projects…
Cybersecurity researchers uncovered a sophisticated malware campaign targeting macOS users through a fraudulent DeepSeek.ai interface.…
A new wave of cyberattacks, dubbed "DeceptiveDevelopment," has been targeting freelance developers through fake job…