Angler Exploit Kit was a prominent web-based exploit kit active primarily in the mid-2010s and widely used in malvertising and drive-by download campaigns to compromise Windows systems through browser and browser plug-in vulnerabilities, especially Adobe Flash Player and also technologies such as Microsoft Silverlight and Oracle Java. It functioned as an exploit delivery platform rather than a single payload family, redirecting victims from compromised or malicious online advertisements and other web traffic sources to landing pages that profiled the browser environment and attempted silent exploitation. Successful exploitation commonly resulted in delivery of additional malware families including Bedep, Vawtrak, Tinba, and Reveton.
The kit was notable for large-scale malvertising operations that redirected visitors from legitimate websites through advertising infrastructure to exploit landing pages without requiring meaningful user interaction. It was associated with drive-by compromise activity and was at times regarded as a leading malware delivery mechanism. Angler operators and affiliates used techniques to improve evasion and effectiveness, including encrypted payload delivery observed by 2015. Campaigns attributed to Angler exploited high-value browser-side vulnerabilities, including Adobe Flash zero-days such as CVE-2015-0311, enabling compromise even on fully patched systems before vendor fixes were released.
Observed post-exploitation outcomes depended on the payload selected by the operator or customer. In documented campaigns, Angler delivered Bedep variants used for ad fraud and click fraud, banking trojans such as Vawtrak and Tinba targeting financial credentials and web sessions, and ransomware such as Reveton. Geographic targeting was also observed, including campaigns delivering Vawtrak to Japanese users and targeting banks in Japan. Angler therefore served as an important criminal distribution layer within a broader malware ecosystem rather than as a standalone credential stealer or ransomware family itself.
Public law-enforcement actions have linked Angler-related malvertising operations to Belarusian suspects including Volodymyr Kadariya and Maksim Silnikau, with allegations that the scheme operated from 2013 through 2022 and delivered malware, scareware, and scams to millions of users through fraudulent advertising and related infrastructure. Angler activity is widely considered to have declined sharply after 2016, and its disappearance was treated as a major turning point in the broader malvertising and exploit-kit landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The ThreatLabZ Research Team reviewed Angler Exploit Kit activity across the cloud and were able to identify multiple instances of Angler Exploit Kit hosting sites serving a new Adobe Flash payload.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These sites ran a version of the Angler exploit kit, which exploited vulnerabilities in visitors' browsers to infect them with malware, and more specifically with Reveton.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon further investigation, we discovered that this appears to be yet another case of a Malvertising campaign leading unsuspecting users to Angler EK instances.
Talos released our detailed investigation of the Angler Exploit Kit... one of the other major payloads was Bedep. | users being compromised by Angler and getting an initial payload of Bedep.
The ThreatLabZ Research Team reviewed Angler Exploit Kit activity across the cloud and were able to identify multiple instances of Angler Exploit Kit hosting sites serving a new Adobe Flash payload that is able to exploit the latest Flash Player version 16.0.0.257.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit kit tied here to a long-running malvertising scheme that is part of a separate prosecution involving the same individual.
An exploit kit tied to a separate New Jersey case involving Silnikau; mentioned only as background and not as the main subject of this reference.
An exploit kit allegedly used as a major malvertising-delivered vehicle to deliver malware to compromised devices of victim internet users.
Browser-based exploit kit historically used in malvertising to exploit client-side vulnerabilities (notably via Flash-era vectors) to deliver malware payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.