logo

Flash zero-day exploit deployed by the ScarCruft APT Group

ID: 4de338d8-f076-463f-a1c3-047d7f0f9861

STIX ID: report--4de338d8-f076-463f-a1c3-047d7f0f9861

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2018-08-06

Last Modified Date: 2018-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab describes “Operation Daybreak,” a ScarCruft APT campaign that used an Adobe Flash zero-day (CVE-2016-4171) to target high-profile victims via spear-phishing and watering-hole sites; the multi-stage exploit chain includes specially crafted SWF files, a reflective DLL (yay_release.dll), abuse of Windows DDE to stealthily execute a VBS installer, and a final CAB-delivered payload with several signed-but-invalid DLLs. The report includes technical vulnerability analysis, exploitation and memory-corruption details, observed victims, C2 infrastructure, and multiple indicators of compromise (IPs, hostnames, MD5s).