Angler, also known as Axpergle, is a commercial exploit kit that automated browser-based compromise and malware delivery, primarily against Windows systems. First observed in 2013, it became a prominent crimeware-as-a-service offering before its disruption in 2016. It rapidly incorporated newly disclosed vulnerabilities, including zero-days, targeting software such as Adobe Flash Player and Microsoft Internet Explorer. Documented exploits included CVE-2015-0310, CVE-2015-0311, CVE-2015-0313, and CVE-2013-2551.
Angler infection chains commonly began with malicious advertisements on legitimate websites or redirects from compromised websites. Landing pages identified browser and plugin versions and selected suitable exploits to silently deliver attacker-supplied payloads. Its evasion features included encrypted exploit delivery, checks for virtualization and security software, and fileless execution that could load Bedep directly into memory. Associated campaigns also used domain shadowing and selective traffic filtering to conceal infrastructure and avoid analysis environments.
Angler distributed ransomware including CryptoWall, TeslaCrypt, AlphaCrypt, and CryptXXX, as well as the Bedep downloader and other malware. Bedep infections could subsequently redirect victims to additional Angler instances delivering ransomware. AdGholas and GooNky were among the malvertising operations that used Angler. Its distribution reached large numbers of website visitors rather than being confined to a particular industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploits tied to the third and fifth most mentioned vulnerabilities (CVE-2015-5119, CVE-2015-5122) were immediately added to EKs including Angler following their disclosure as a Adobe Flash zero-days in the July 2015 Hacking Team leak.
The top vulnerability CVE 2015-0313 – affecting Flash Player 16.0.0.296 and identified by Adobe as critical – was patched on February 2, 2015 and seen as a zero day exploit as early as December 2014.
Exploits tied to the third and fifth most mentioned vulnerabilities (CVE-2015-5119, CVE-2015-5122) were immediately added to EKs including Angler following their disclosure as a Adobe Flash zero-days in the July 2015 Hacking Team leak.
We refer to this type of faulty implementation as a “degraded” mode, and it is something that we have observed in the past with CVE-2014-8439 and CVE-2015-0310 in Angler. | We refer to this type of faulty implementation as a 'degraded' mode, and it is something that we have observed in the past with CVE-2014-8439 and CVE-2015-0310 in Angler.
Degraded exploit implementations were previously observed with CVE-2014-8439 and CVE-2015-0310 in Angler. | We refer to this type of faulty implementation as a 'degraded' mode, and it is something that we have observed in the past with CVE-2014-8439 and CVE-2015-0310 in Angler.
We initially suspected that the exploit was for CVE-2016-1001 as in Angler. A CVE-2016-1001 string was also spotted in a Nuclear Pack exploit. | We refer to this type of faulty implementation as a 'degraded' mode, and it is something that we have observed in the past with CVE-2014-8439 and CVE-2015-0310 in Angler.
Victims are redirected by a Flash exploit to a site hosting the Angler exploit kit, and Angler drops the CryptoLocker variant.
Victims are redirected by a Flash exploit to a site hosting the Angler exploit kit, and Angler drops the CryptoLocker variant.
...six zero-day vulnerabilities (... CVE-2015-5123 for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-2425 for Internet Explorer) ... being released into the wild.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When Angler disappeared from the exploit kit market, the “GooNky” actors migrated their malvertising campaign to Neutrino EK.
Initially, the gang behind AdGholas had been using the Angler and Neutrino exploit kits.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit kit distributed through malicious online advertisements that silently infected visitors to legitimate websites.
Notorious exploit kit widely used to deploy malware; Silnikau was separately charged with participating in its distribution.
An exploit kit delivered via malvertising that scans browsers and browser plugins for vulnerabilities and exploits them to infect users.
Exploit kit used by cybercriminals to find and exploit known software vulnerabilities in order to deploy malware quickly and efficiently.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.