logo

Flash zero-day exploit deployed by the ScarCruft APT Group

ID: 8240c377-c4d8-470e-b433-dbe0689b384f

STIX ID: report--8240c377-c4d8-470e-b433-dbe0689b384f

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2016-06-17

Last Modified Date: 2016-06-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab documents Operation Daybreak, a targeted campaign by the ScarCruft APT that used a zero-day Adobe Flash Player vulnerability (CVE-2016-4171) delivered via spear-phishing and compromised websites to achieve remote code execution. The report details the multi-stage exploit chain (three SWFs), memory-corruption root cause, evasive techniques including RC4+Base64 delivery and an undocumented DDE-based execution path to bypass endpoint protections, final payloads (CAB with signed-but-invalid DLLs), C2 indicators, MD5s, and a small set of high-profile victims across multiple countries.