Angler Exploit Kit is a web-based exploitation framework used by cybercriminals to compromise visitors through vulnerabilities in browsers and associated plug-ins and install additional malware. It targeted Windows systems through components including Adobe Flash Player, Microsoft Silverlight, and Oracle Java. Its distribution chains commonly used malvertising on legitimate websites to silently redirect visitors to exploit landing pages, enabling drive-by infections without requiring users to download or run an attachment.
Angler used obfuscated JavaScript, browser plug-in detection, and encrypted exploit or payload delivery. It exploited Adobe Flash Player vulnerability CVE-2015-0311 while the vulnerability was still a zero-day, delivering malware to systems running then-current Flash releases. Observed payloads included TeslaCrypt and Reveton ransomware, the Bedep Trojan, and the Tinba and Vawtrak banking Trojans. Angler delivered Vawtrak to Japanese users in February 2016; credential theft, ransomware encryption, and advertising fraud were functions of its downstream payloads rather than of the exploit kit itself.
Angler was associated with the Russian Lurk gang and was used in Zain Qaiser's Reveton malvertising operation. Its disappearance in June 2016 followed Russian arrests of Lurk gang members. U.S. prosecutions have also named Maksim Silnikau, Volodymyr Kadariya, and Andrei Tarasov in connection with an alleged malvertising scheme involving Angler and other malicious software.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In our analysis, the exploit kit delivered a malicious Flash object containing an exploit against CVE-2015-0311. The payload for this exploit was a TeslaCrypt sample.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These sites ran a version of the Angler exploit kit, which exploited vulnerabilities in visitors' browsers to infect them with malware, and more specifically with Reveton.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon further investigation, we discovered that this appears to be yet another case of a Malvertising campaign leading unsuspecting users to Angler EK instances.
Talos released our detailed investigation of the Angler Exploit Kit... one of the other major payloads was Bedep. | users being compromised by Angler and getting an initial payload of Bedep.
The ThreatLabZ Research Team reviewed Angler Exploit Kit activity across the cloud and were able to identify multiple instances of Angler Exploit Kit hosting sites serving a new Adobe Flash payload that is able to exploit the latest Flash Player version 16.0.0.257.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit kit tied here to a long-running malvertising scheme that is part of a separate prosecution involving the same individual.
An exploit kit tied to a separate New Jersey case involving Silnikau; mentioned only as background and not as the main subject of this reference.
An exploit kit allegedly used as a major malvertising-delivered vehicle to deliver malware to compromised devices of victim internet users.
Browser-based exploit kit historically used in malvertising to exploit client-side vulnerabilities (notably via Flash-era vectors) to deliver malware payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.