Astrum

Stegano EK - Status: Active

References:
  • Say Hello to Astrum EK - 2014-09-14 - MDNC - Kafeine Astrum
  • Readers of popular websites targeted by stealthy Stegano exploit kit hiding in pixels of malicious ads - 2016-12-06 - Eset Astrum AdGholas
  • Will Astrum Fill the Vacuum in the Exploit Kit Landscape? - 2017-05-18 - Trend Micro - Joseph C. Chen Astrum CVE-2017-0022 CVE-2016-1019 CVE-2016-4117
  • More Reading:

  • CVE-2014-0569 (Flash Player) integrating Exploit Kit - 2014-10-21 - MDNC - Kafeine CVE-2014-0569 Chthonic Fiesta Angler Astrum Sweet Orange FlashPack RIG Magnitude KovCoreG Kovter
  • Microsoft Patches CVE-2016-3351 Zero-Day, Exploited By AdGholas and GooNky Malvertising Groups - 2016-09-13 - Proofpoint - Kafeine CVE-2016-3351 GooNky AdGholas Angler Astrum
  • Astrum (aka Stegano) EK has integrated CVE-2017-0022 (infoleak) for filtering in its landing - 2017-03-25 - Twitter - Kafeine CVE-2017-0022 Astrum
  • AdGholas Malvertising Campaign Using Astrum EK to Deliver Mole Ransomware - 2017-06-20 - Proofpoint - Kafeine AdGholas Astrum Mole
  • AdGholas Malvertising Campaign Employs Astrum Exploit Kit - 2017-06-20 - Trend Micro - Joseph C. Chen AdGholas Astrum Mole