An In-Depth Look at How Pawn Storm’s Java Zero-Day Was Used
ID: 0c55b989-f28c-4596-8566-2bad502235e7
STIX ID: report--0c55b989-f28c-4596-8566-2bad502235e7
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2015-10-31
Last Modified Date: 2015-10-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro documents Operation Pawn Storm’s targeted use of a Java zero-day (CVE-2015-2590) delivered via spearphishing to execute a multi-stage infection that drops a PE and a SEDNIT DLL backdoor/keylogger; the report includes infection chain diagrams, file hashes, network traffic patterns, C2 domains/IPs, stable IOCs, and recommended mitigations (patching and Trend Micro detection rules).
