Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Slicing and Dicing CVE-2018-5002 Payloads: New CHAINSHOT Malware

released on 2018-09-07 @ 05:04:25 PM
This story begins with one of our blog authors, who, following the discovery of a new Adobe Flash 0-day, found several documents using the same exploit that were used in targeted attacks. We were also able to collect network captures including the encrypted malware payload. Armed with these initial weaponized documents, we uncovered additional attacker network infrastructure, were able to crack the 512-bit RSA keys, and decrypt the exploit and malware payloads. We have dubbed the malware ‘CHAINSHOT’, because it is a targeted attack with several stages and every stage depends on the input of the previous one.