Flash zero-day exploit deployed by the ScarCruft APT Group
ID: 4de338d8-f076-463f-a1c3-047d7f0f9861
STIX ID: report--4de338d8-f076-463f-a1c3-047d7f0f9861
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2018-08-06
Last Modified Date: 2018-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab describes “Operation Daybreak,” a ScarCruft APT campaign that used an Adobe Flash zero-day (CVE-2016-4171) to target high-profile victims via spear-phishing and watering-hole sites; the multi-stage exploit chain includes specially crafted SWF files, a reflective DLL (yay_release.dll), abuse of Windows DDE to stealthily execute a VBS installer, and a final CAB-delivered payload with several signed-but-invalid DLLs. The report includes technical vulnerability analysis, exploitation and memory-corruption details, observed victims, C2 infrastructure, and multiple indicators of compromise (IPs, hostnames, MD5s).
