Blackhole Exploit Kit was a widely used web-based exploit kit active primarily in the early 2010s and heavily involved in malware distribution campaigns targeting organizations and end users, including U.S. companies and financial institutions. It functioned as an exploit delivery platform that redirected victims from compromised or maliciously injected web content to attacker-controlled landing infrastructure, where browser-side exploitation was used to install follow-on malware. Blackhole was commonly used to distribute other malware families rather than serving as the final payload itself.
Observed campaigns linked to Blackhole included traffic redirection from compromised websites and server-side web compromises that injected malicious redirects into normal browsing sessions. In some cases, infected website files appended hidden iframe redirects that sent visitors onward to Blackhole infrastructure; in others, trojanized web server components intermittently redirected users to exploit-kit landing pages. The kit was also associated with large-scale criminal hosting ecosystems that provided resilient infrastructure for malware operations, botnet activity, and theft of banking credentials.
Blackhole played a significant role in cybercrime operations between roughly 2009 and 2015, appearing alongside major banking malware ecosystems such as Zeus, SpyEye, and Citadel. Its operational purpose was initial compromise and malware delivery, enabling downstream infections that could support credential theft, botnet formation, and broader post-compromise criminal activity. The kit was broadly recognized by defenders as a major malware distribution mechanism of its era.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
the defendants pleaded guilty to conspiring to engage in a Racketeer Influenced Corrupt Organization (RICO) arising from their providing “bulletproof hosting” services between 2008 and 2015, which were used by cybercriminals to distribute malware and attack financial institutions and victims throughout the United States.
Dedicated TDS. Those TDS can be hidden behind forest of redirectors/reverse proxies. They are redirecting traffic based on country/browser depending on the needs
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit hosted by the bulletproof hosting organization and used by cybercriminal clients to distribute malware and attack victims.
An exploit kit that earlier versions of the malware redirected victims to as a follow-on malicious stage.
Exploit kit hosted by the bulletproof hosting organization and used in campaigns attacking U.S. companies and financial institutions.
An exploit kit widely used to distribute malware, with 323 associated IP addresses included by Spamhaus.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.