Flash zero-day exploit deployed by the ScarCruft APT Group
ID: 8240c377-c4d8-470e-b433-dbe0689b384f
STIX ID: report--8240c377-c4d8-470e-b433-dbe0689b384f
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2016-06-17
Last Modified Date: 2016-06-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab documents Operation Daybreak, a targeted campaign by the ScarCruft APT that used a zero-day Adobe Flash Player vulnerability (CVE-2016-4171) delivered via spear-phishing and compromised websites to achieve remote code execution. The report details the multi-stage exploit chain (three SWFs), memory-corruption root cause, evasive techniques including RC4+Base64 delivery and an undocumented DDE-based execution path to bypass endpoint protections, final payloads (CAB with signed-but-invalid DLLs), C2 indicators, MD5s, and a small set of high-profile victims across multiple countries.
