logo

BlackOasis APT and new targeted attacks leveraging zero-day exploit

ID: c1d52e38-4b2b-4f29-b967-c008f8cdd71e

STIX ID: report--c1d52e38-4b2b-4f29-b967-c008f8cdd71e

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2017-10-17

Last Modified Date: 2017-10-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky researchers describe BlackOasis APT using a Flash zero-day (CVE-2017-11292) embedded in an Office document to deploy FinSpy (mo.exe). The report includes technical exploit and payload analysis (custom packer, VM, shellcode), observed IOCs (89.45.67.107 and MD5 4a49135d2ecc07085a8b7c5925a36c0a), affected targets across multiple countries, and mitigation recommendations such as applying the Flash patch and layered defenses.