Watering Hole Attack on Aerospace Firm Exploits CVE-2015-5122 to Install IsSpace Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
ID: ed006f16-171b-47a6-94f7-4bd7b34bb6b1
STIX ID: report--ed006f16-171b-47a6-94f7-4bd7b34bb6b1
Threat Score
75/100
Uploaded: 2026-08-21
Published Date: 2015-07-22
Last Modified Date: 2015-07-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents a watering hole attack against an aerospace firm that used a CVE-2015-5122 Flash exploit to drop and execute IsSpace backdoor, detailing shellcode, payloads, C2 infrastructure, and potential links to the NFlog family and Southeast Asia threat actors.
