RIG Exploit Kit is a financially motivated exploit kit active since 2014 that has been widely used in drive-by compromise chains to deliver a variety of malware payloads. It is commonly deployed through compromised or malicious websites and malvertising-driven redirection chains, where victims are funneled to exploit landing pages that profile the browser environment and attempt client-side exploitation. Reported payloads delivered through RIG have included banking trojans, downloader trojans, ransomware, cryptocurrency miners, information stealers, and other follow-on malware families such as Purple Fox and Gootkit-associated infection chains.
RIG is associated with web-based initial access rather than being a payload itself. Campaigns using RIG have leveraged browser and plugin vulnerabilities, particularly in Adobe Flash Player and Internet Explorer-era scripting engines, to execute code on victim systems and retrieve secondary malware. Observed operations have also used fingerprinting and anti-bot techniques to evade researchers and automated analysis systems before serving exploits. In some campaigns, RIG formed part of broader traffic distribution and malvertising ecosystems that redirected users from ordinary websites or malicious advertisements to exploit infrastructure.
The kit has been used by financially motivated cybercrime operations and has appeared in campaigns targeting general internet users as well as business environments, depending on the payload delivered. Its long operational history and repeated use as a malware delivery platform make it a notable exploit kit in post-Angler web exploitation activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Rig exploit kit, for instance, is known for delivering various payloads... Also delivered by the Rig exploit kit, Purple Fox previously used the Nullsoft Scriptable Install System (NSIS) tool to retrieve and execute its payload.
The Rig exploit kit, for instance, is known for delivering various payloads... Also delivered by the Rig exploit kit, Purple Fox previously used the Nullsoft Scriptable Install System (NSIS) tool to retrieve and execute its payload.
The Rig exploit kit, for instance, is known for delivering various payloads... Also delivered by the Rig exploit kit, Purple Fox previously used the Nullsoft Scriptable Install System (NSIS) tool to retrieve and execute its payload.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the user accesses a malicious site hosting one of Rig’s landing pages, there are three methods used to ultimately redirect the user to a malicious PowerShell script | Once the user accesses a malicious site hosting one of Rig’s landing pages
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit referenced in the context of using fingerprinting/anti-bot techniques to evade scanners and selectively deliver exploit/payload chains.
RIG Exploit Kit is a toolkit hosted on Media Land infrastructure, used to deliver various malware via browser exploits.
An exploit kit used as a propagation vector to deliver Gootkit via compromised web pages containing exploits.
Earlier exploit kit used by the PseudoGate campaign before migration to other kits.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.