ZeroHour

Search: “Neutrino exploit kit”

51 stories

Locky Ransomware Installed Through Nuclear EK

Unit 42 reports Locky ransomware delivered through the Nuclear exploit kit using Flash exploits, adding a drive-by path to existing malspam distribution.

Unit 42 observed Locky ransomware being delivered by the Nuclear exploit kit in March 2016 via Flash exploits, following February reports of Neutrino EK distributing Locky. Infections follow a drive-by chain through a gate to the Nuclear EK, which either installs Locky directly or drops a downloader that retrieves it from another domain. Locky retains two distribution paths: malspam with malicious Office macros or JavaScript attachments and exploit kit traffic triggered by casual web browsing.

Palo Alto Unit 42 · Aug 17, 2026Ransomware in the wild1

Afraidgate: Major Exploit Kit Campaign Swaps Locky Ransomware for CryptXXX

Unit 42 reports the Afraidgate campaign switched from Nuclear EK delivering Locky to Angler EK delivering CryptXXX via the Bedep downloader.

Unit 42 reported that the Afraidgate campaign, which uses gates registered through FreeDNS at afraid.org, switched in mid-April 2016 from Nuclear EK distributing Locky ransomware to Angler EK distributing CryptXXX. The Angler/Bedep/CryptXXX combination also spread from the pseudo-Darkleech campaign, with Bedep acting as a fileless, memory-resident downloader that also installs click-fraud malware. Recent Bedep updates detect virtual machines and alter behavior, complicating analyst investigation. Unit 42 published gate, EK, and post-infection indicators including gate IP 185.118.164.42 and associated domains.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild

Campaign Evolution: Darkleech to Pseudo

Unit 42 traces the pseudo-Darkleech campaign, which compromises websites to inject scripts redirecting visitors to exploit kits delivering ransomware.

Palo Alto Networks Unit 42 analyzed the evolution of the pseudo-Darkleech campaign, which injects malicious script into compromised Apache, IIS and WordPress sites to redirect visitors to exploit kits such as Angler and Neutrino. The original Darkleech Apache module infected thousands of servers starting in 2012 and delivered Blackhole EK until that kit disappeared after Paunch's 2013 arrest. From 2015 onward, pseudo-Darkleech delivered ransomware families like CryptoWall and TeslaCrypt, and by early 2016 its injected scripts added obfuscated numeric blocks with frequently changing separator characters. Unit 42 tracks these patterns to help defenders identify compromised websites.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild