Operation Daybreak
ID: 84cbd52b-47f7-49f3-b0b7-04055887e35d
STIX ID: report--84cbd52b-47f7-49f3-b0b7-04055887e35d
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-03-12
Last Modified Date: 2019-03-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab describes 'Operation Daybreak', a ScarCruft APT campaign that deployed a zero-day Adobe Flash vulnerability (CVE-2016-4171) via spear-phishing and watering-hole techniques to deliver a multi-stage payload. The report analyzes the SWF exploit and memory corruption, documents a novel Windows DDE-based method used to execute payloads to evade AV detection, lists malware samples (MD5s), C2 infrastructure, invalid digital signatures, and several high-profile victims across multiple countries.
