Nuclear is an exploit kit. The provided content identifies Nuclear as one of the common exploit kits alongside Angler/Axpergle and Neutrino, and notes it among exploit kits such as Blackhole and Phoenix that were active historically before later kits such as Rig, Magnitude, and Grandsoft. The content states that exploit kits are automated tools used by cybercriminals to quickly identify and exploit known software vulnerabilities in order to install malware. They commonly target outdated software including Adobe Flash Player, Adobe Reader, web browsers, Oracle Java, and Sun Java. Infection vectors mentioned for exploit kits include malicious websites, email attachments, and malicious advertisements on legitimate websites. One reference states that Angler and Nuclear exploit kit developers implemented encrypted exploit delivery using Diffie-Hellman key exchange to help bypass exploit-detection appliances. Another source compares a custom espionage exploit kit used by Sednit/Sofacy to Angler and Nuclear, indicating Nuclear was a recognized benchmark for exploit-kit behavior. No high-confidence actor attribution, specific payload family, or unique indicators of compromise for Nuclear itself are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...six zero-day vulnerabilities (... CVE-2015-2425 for Internet Explorer) ... being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5123 for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5122 ... for Adobe Flash; ...) being released into the wild.
...six zero-day vulnerabilities (... CVE-2015-5119, CVE-2015-5122 and CVE-2015-5123 for Adobe Flash; ...) ... being released into the wild.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit referenced as a common example of automated tooling used to exploit software vulnerabilities and deliver malware.
Nuclear is described as an exploit kit whose developers implemented encrypted exploit delivery via Diffie-Hellman key exchange to evade exploit detection appliances.
Exploit kit formerly traded on Russian forums.
Macro virus that became fairly common in 1996.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.