BlackOasis__2017__BlackOasis.pdf
ID: 56a02a0a-bf06-4ace-9717-a818bf96eee3
STIX ID: report--56a02a0a-bf06-4ace-9717-a818bf96eee3
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2017-10-24
Last Modified Date: 2017-10-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky describes a targeted BlackOasis APT campaign that exploited an Adobe Flash zero-day (CVE-2017-11292) delivered via Microsoft Office documents to deploy Gamma International’s FinSpy spyware; the report includes technical exploit and shellcode analysis, infection chain (ActiveX Flash, staged shellcode, download of mo.exe), persistence via DLL search-order hijacking, C2 indicators (89.45.67.107), an MD5 for the payload, victim targeting across Middle Eastern and other countries, and mitigation recommendations.
