logo

An In-Depth Look at How Pawn Storm’s Java Zero-Day Was Used

ID: 0c55b989-f28c-4596-8566-2bad502235e7

STIX ID: report--0c55b989-f28c-4596-8566-2bad502235e7

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-10-31

Last Modified Date: 2015-10-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro documents Operation Pawn Storm’s targeted use of a Java zero-day (CVE-2015-2590) delivered via spearphishing to execute a multi-stage infection that drops a PE and a SEDNIT DLL backdoor/keylogger; the report includes infection chain diagrams, file hashes, network traffic patterns, C2 domains/IPs, stable IOCs, and recommended mitigations (patching and Trend Micro detection rules).