logo

BlackOasis__2017__BlackOasis.pdf

ID: 56a02a0a-bf06-4ace-9717-a818bf96eee3

STIX ID: report--56a02a0a-bf06-4ace-9717-a818bf96eee3

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2017-10-24

Last Modified Date: 2017-10-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky describes a targeted BlackOasis APT campaign that exploited an Adobe Flash zero-day (CVE-2017-11292) delivered via Microsoft Office documents to deploy Gamma International’s FinSpy spyware; the report includes technical exploit and shellcode analysis, infection chain (ActiveX Flash, staged shellcode, download of mo.exe), persistence via DLL search-order hijacking, C2 indicators (89.45.67.107), an MD5 for the payload, victim targeting across Middle Eastern and other countries, and mitigation recommendations.