Capesand is a new Exploit Kit that appeared in the threat landscape
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-2419 | Memory Corruption RCE in Microsoft Internet Explorer JScript Engine CVE-2015-2419 is a memory corruption flaw (CWE-119) in the JScript engine used by Microsoft Internet Explorer, allowing remote attackers to execute arbitrary code or cause a denial of service through a crafted website. It is triggered when a user visits an attacker-controlled page whose JScript content corrupts memory in the affected browser process. A successful attacker gains remote code execution in the context of the logged-on user (or crashes the browser), which makes drive-by and exploit-kit delivery routes viable. Any Windows user running the affected versions of Internet Explorer at the time of disclosure was exposed, and Microsoft shipped fixes as part of its July 2015 security updates. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28), carries a 53.4% EPSS (99th percentile), and related reporting places it among the top vulnerabilities used by exploit kits in 2015-2016. Do: Apply Microsoft's July 2015 security updates for Internet Explorer per vendor instructions, as required by the CISA KEV catalog, and verify that any legacy Windows systems still running Internet Explorer have received them. Because exploitation typically occurs via drive-by web attacks, retire or fully patch IE on client endpoints and keep endpoint protection enabled to catch exploit-kit delivery. Confirm no workstations remain on unpatched IE builds, since this entry has been in CISA KEV since March 2022 and exploitation probability remains high (EPSS 53.4%). | — | 53% | KEV |
| masshundreds of millions of Windows users running Internet Explorer at the time of disclosure | |
| CVE-2018-15982 | Use-After-Free in Adobe Flash Player Allows Arbitrary Code Execution CVE-2018-15982 is a use-after-free flaw (CWE-416) in Adobe Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier, in which Flash frees memory that is subsequently reused, corrupting process memory. It is triggered when Flash processes crafted Flash content, most notably embedded in Microsoft Office documents, requiring a user to open or view the malicious content (CVSS attack vector is local with user interaction required). Successful exploitation gives the attacker arbitrary code execution with the privileges of the user viewing the content. Affected users include anyone running the listed Flash Player versions, including the Flash Player Installer and the Adobe-supplied Flash plugin shipped with Red Hat Enterprise Linux Desktop, Server and Workstation. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15) with known ransomware use, a public exploit is available on Exploit-DB, and EPSS assigns a top-percentile 89.1% probability of exploitation within 30 days. Do: Flash Player is end-of-life: per CISA's required action, remove or disconnect Flash wherever it is still in use; if Flash must remain, update beyond the affected 31.0.0.153/31.0.0.108 builds and update the flash-plugin package on Red Hat Enterprise Linux. Mitigate the known delivery vector by blocking or disabling embedded Flash (SWF) content in Microsoft Office documents and mail clients, and hunt for suspicious documents with embedded Flash given the known in-the-wild and ransomware use. | 7.8 | 89% | KEV ransomware PoC |
| mass≈100M+ endpoints historically (Flash was preinstalled/bundled across most Windows desktops and shipped with Chrome and RHEL in 2018); only residual legacy… | |
| CVE-2018-4878 | Use-After-Free RCE in Adobe Flash Player before 28.0.0.161 CVE-2018-4878 is a use-after-free (CWE-416) in Adobe Flash Player before 28.0.0.161, caused by a dangling pointer in the Primetime SDK's media-player handling of listener objects. An attacker triggers it by persuading a user to open attacker-controlled Flash content — typically a malicious SWF delivered via email, Office documents, or malvertising/exploit kits — because the CVSS vector (AV:L, UI:R) requires local user interaction. Successful exploitation yields arbitrary code execution with the privileges of the user running Flash. Anyone running a vulnerable Flash Player was exposed, including Red Hat Enterprise Linux Desktop/Server/Workstation users running Red Hat's packaged Flash plugin. The flaw was exploited as a zero-day in January–February 2018 (documented by McAfee and distributed alongside the Fallout exploit kit), and it remains in CISA's KEV with known ransomware use. Do: Upgrade Adobe Flash Player to 28.0.0.161 or later, including Red Hat's flash-plugin package on RHEL Desktop/Server/Workstation. Because Flash is now end-of-life, CISA's required KEV action is to remove or disconnect Flash entirely where still in use — audit browsers, Office configurations, and legacy RHEL hosts for residual Flash installs, and block SWF content delivered via email and the web. Given confirmed in-the-wild exploitation, known ransomware use, and 89.5% EPSS, prioritize this in remediation tracking. | 7.8 | 90% | KEV ransomware PoC ×2 |
| mass≈ hundreds of millions of desktop installs at time of disclosure; residual unmigrated installs now unknown (Flash is end-of-life) | |
| CVE-2018-8174 | Out-of-Bounds Write RCE in Microsoft Windows VBScript Engine CVE-2018-8174 is an out-of-bounds write (CWE-787) in the Microsoft Windows VBScript engine, caused by the way it handles objects in memory. An attacker triggers it by convincing a user to visit a specially crafted website or open crafted content that invokes the VBScript engine (for example via Internet Explorer or a document preview), requiring user interaction. Successful exploitation yields remote code execution with the privileges of the logged-on user, enabling program installation, data theft and account takeover. All listed Windows client and server releases are affected: Windows 7, 8.1, RT 8.1, Windows 10 (1607-1803), and Windows Server 2008/2008 R2, 2012/2012 R2, 2016. Exploitation is in the wild: the flaw was fixed in the May 2018 Patch Tuesday, is listed in CISA KEV with known ransomware use, and public PoCs (0patch, ExploitDB 44741) and exploit kit usage have been documented; EPSS puts its 30-day exploitation probability at 88.5%. Do: Apply Microsoft's May 2018 security updates (and any later cumulative or Extended Security Updates) to every listed Windows client and server release, as required by the CISA KEV listing, prioritizing internet-reachable and user-facing systems given known ransomware use. Upgrade out-of-support platforms (Windows 7/8.1/RT 8.1, Server 2008/2008 R2, 2012/2012 R2) to supported builds or ensure ESU coverage. As interim mitigation, block VBScript execution in Internet Explorer web zones using Microsoft's documented Group Policy/registry settings, and hunt for prior exploitation on legacy systems. | 7.5 | 88% | KEV ransomware PoC ×2 |
| masshundreds of millions of Windows PCs and servers (affected desktop releases dominated the ~1B+ device Windows install base at disclosure) | |
| CVE-2019-0752 | Type Confusion RCE in Microsoft Internet Explorer Scripting Engine CVE-2019-0752 is a type confusion (CWE-843) memory corruption vulnerability in the way the scripting engine used by Internet Explorer handles objects in memory, and it is distinct from the related scripting-engine flaws CVE-2019-0739, CVE-2019-0753, and CVE-2019-0862. An attacker triggers it by convincing a user to view attacker-controlled or attacker-crafted web content in Internet Explorer, where malformed handling of in-memory objects corrupts memory (the CVSS vector reflects a network attack requiring user interaction with high attack complexity). Successful exploitation yields remote code execution with the privileges of the current user, giving the attacker high confidentiality, integrity, and availability impact on the host. Anyone running Internet Explorer on supported Windows client or server systems is exposed; the provided data does not specify exact affected version ranges, though the public proof-of-concept was demonstrated on Windows 10 1809 (build 17763.316). Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15) with known ransomware use, carries a top-percentile EPSS score of 81.6%, and contemporary reporting ties scripting-engine flaws like this to exploit kits (e.g., RIG) delivering malware such as Dridex. Do: Apply Microsoft's security updates that address CVE-2019-0752 via Windows Update or WSUS, per the CISA KEV required action, and audit legacy Windows clients and servers for any that have not been patched. Where updates are impractical (e.g., out-of-support systems), stop using Internet Explorer as the default browser, restrict or disable scripting in the Internet zone, and consider blocking IE-facing access to untrusted sites. Because exploit kits (e.g., RIG) and ransomware operators have leveraged IE scripting-engine flaws, prioritize patching user workstations and shared/multi-user systems. | 7.5 | 82% | KEV ransomware PoC |
| masshundreds of millions of Windows devices/users with Internet Explorer present |
Full article635 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 08, 2019

A recently discovered exploit kit dubbed Capesand is being involved in live attacks despite the fact that it’s still under development.
In October 2019, researchers at TrendMicro discovered a new exploit kit dubbed Capesand that is being involved in live attacks. The tool was discovered while analyzing a malvertising campaign employing the RIG EK to deliver DarkRAT and njRAT.
Experts pointed out that the code of the Capesand exploit kit is quite simple compared with other exploit kits.
Capesand attempts to exploit recent vulnerabilities in Adobe Flash and Microsoft Internet Explorer (IE) and also a 2015 vulnerability for IE. Operators behind the new exploit kit are reusing source code from a publicly shared exploit kit code, experts noticed that the EK is still under development.
“In the middle of October, we found a malvertising campaign using the Rig exploit kit and delivering DarkRAT and njRAT malware. By the end of October, however, we noticed a change in the malvertisement and the redirection was no longer to the Rig exploit kit.” reads the analysis published by Trend Micro. “The cybercriminals shifted to loading an exploit kit we were unfamiliar with. Investigating further led us to a panel provided for this unknown exploit kit to customers. The panel has the name Capesand on it and directly provides the source code of the exploit kit.”
Trend Micro uncovered a malvertising campaign that was delivered from the ad network straight to the victim’s browser, it was appearing as a blog talking about blockchain.
The analysis of the source code of the page revealed that its content was copied using the website copying tool HTTrack and contains a hidden iframe used to load the exploit kit.
The Capesand panel allows its operators to check the status of exploit kit usage and download frontend source code to deploy on their servers.
“In the case we identified, the campaign deployed it with their fake blockchain malvertisement. While we checked the frontend source code, we found that it looks similar to a very old exploit kit called Demon Hunter, leading us to believe that Capesand is probably derived from it.” continues the analysis.
The list of vulnerabilities exploited by the Capesand EK includes CVE-2018-4878 (Adobe Flash), along with CVE-2018-8174 and CVE-2019-0752 (Internet Explorer).
Another interesting aspect of the Capesand EK is that the exploits are not included in the frontend EK source code package. Experts discovered that Capesand delivers a specific exploit code by requesting it to a server API..
The API request includes the following information on the victims:
- Requested exploit name
- Exploit URL in configuration
- Victim’s IP address
- Victim’s browser user-agent
- Victim’s HTTP referrer
The information is AES encrypted with a pre-generated API key inside a configuration file.
Further investigation allowed the experts to discover a version of Capesand using exploits for the following vulnerabilities:
- CVE-2015-2419 (IE);
- CVE-2018-4878 and CVE-2018-15982 (Adobe Flash)
- CVE-2018-8174 (IE);
“But we did not see the exploit for the newer IE vulnerability CVE-2019-0752 indicated in their source code.” states Trend Micro. “This leads us to believe that the kit is still under development and has yet to fully integrate the exploits the cybercriminals planned to use.”
Experts discovered that crooks are also distributing malicious landing pages via mirrored versions of legitimate websites and use domain names similar to the originals to avoid detection.
“Moreover, the architecture is evolving in the direction of distributing the malicious landing pages via mirrored versions of legitimate websites under domain names similar to the originals’.” concludes the analysis.
“In addition, its exploits are delivered as a service accessible through a remote API — an efficient method to keep the exploits private and reusable across different deployment mechanisms,”
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Capesand exploit kit, malware)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/93577/malware/capesand-exploit-kit.html