Campaign Evolution: pseudo
Unit 42 traces the pseudo-Darkleech campaign's 2016 shift from Angler to Neutrino to Rig exploit kits and rotating ransomware payloads.
Unit 42 documents how the pseudo-Darkleech exploit kit campaign evolved through 2016, switching from Angler EK to Neutrino EK in June and to Rig EK in September after Neutrino ceased operations. Payloads rotated from TeslaCrypt to CryptXXX, CrypMIC, and finally Cerber ransomware by October 2016. Injected script on compromised websites changed from 12,000-18,000 character obfuscated blocks to short, unobfuscated hidden iframes starting July 1, 2016.
Campaign Evolution: Darkleech to Pseudo
Unit 42 traces the pseudo-Darkleech campaign, which compromises websites to inject scripts redirecting visitors to exploit kits delivering ransomware.
Palo Alto Networks Unit 42 analyzed the evolution of the pseudo-Darkleech campaign, which injects malicious script into compromised Apache, IIS and WordPress sites to redirect visitors to exploit kits such as Angler and Neutrino. The original Darkleech Apache module infected thousands of servers starting in 2012 and delivered Blackhole EK until that kit disappeared after Paunch's 2013 arrest. From 2015 onward, pseudo-Darkleech delivered ransomware families like CryptoWall and TeslaCrypt, and by early 2016 its injected scripts added obfuscated numeric blocks with frequently changing separator characters. Unit 42 tracks these patterns to help defenders identify compromised websites.
EITest Campaign Evolution: From Angler EK to Neutrino and Rig
Unit 42 details the EITest campaign's shift from Angler to Neutrino and Rig exploit kits while distributing ransomware, downloaders, and banking trojans.
Unit 42 updated its tracking of the EITest campaign, first identified in October 2014, which compromises websites with injected scripts that redirect victims through a gate to exploit kits. After Angler EK disappeared in June 2016, EITest switched to Neutrino and then primarily used Rig EK by August 2016. In September 2016 the campaign began using hex-obfuscated JavaScript and simplified gate URLs, while continuing to distribute payloads including Gootkit, Cerber, Bart, CryptFile2, Vawtrak, Ursnif, and Tinba. Gate infrastructure consistently reused IP blocks such as 85.93.0.0/24 even as domain names changed.