logo

Operation Daybreak

ID: 84cbd52b-47f7-49f3-b0b7-04055887e35d

STIX ID: report--84cbd52b-47f7-49f3-b0b7-04055887e35d

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-03-12

Last Modified Date: 2019-03-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab describes 'Operation Daybreak', a ScarCruft APT campaign that deployed a zero-day Adobe Flash vulnerability (CVE-2016-4171) via spear-phishing and watering-hole techniques to deliver a multi-stage payload. The report analyzes the SWF exploit and memory corruption, documents a novel Windows DDE-based method used to execute payloads to evade AV detection, lists malware samples (MD5s), C2 infrastructure, invalid digital signatures, and several high-profile victims across multiple countries.