BlackOasis APT and new targeted attacks leveraging zero-day exploit
ID: c1d52e38-4b2b-4f29-b967-c008f8cdd71e
STIX ID: report--c1d52e38-4b2b-4f29-b967-c008f8cdd71e
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2017-10-17
Last Modified Date: 2017-10-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky researchers describe BlackOasis APT using a Flash zero-day (CVE-2017-11292) embedded in an Office document to deploy FinSpy (mo.exe). The report includes technical exploit and payload analysis (custom packer, VM, shellcode), observed IOCs (89.45.67.107 and MD5 4a49135d2ecc07085a8b7c5925a36c0a), affected targets across multiple countries, and mitigation recommendations such as applying the Flash patch and layered defenses.
