Fallout Exploit Kit is a web-based exploit kit used in malvertising-driven drive-by compromise campaigns to deliver follow-on malware to selected victims. Active by at least 2018, it was observed targeting users across Japan, Korea, the Middle East, Southern Europe, and other Asia-Pacific regions. The kit fingerprints visiting browsers and serves exploit content only to profiles that match operator-defined criteria, using multi-stage redirection chains and intermediary infrastructure to route victims from legitimate advertising traffic to exploit landing pages.
Fallout Exploit Kit has been documented exploiting CVE-2018-15982 in Adobe Flash Player and CVE-2018-8174 in the Internet Explorer VBScript engine to achieve initial code execution on Windows systems. It has been used to distribute multiple malware families, including Vidar, GandCrab, SmokeLoader, and ACBackdoor, and it also appeared in the broader PseudoGate ecosystem before that campaign shifted to Spelevo Exploit Kit. In observed intrusion chains, Fallout delivered Vidar as an infostealer and downloader that subsequently retrieved GandCrab ransomware, combining credential and data theft with file encryption for increased monetization.
The kit is best characterized as an exploit-driven delivery platform rather than a standalone payload. Its operational role centers on victim profiling, exploit-based initial access, and handoff to secondary malware selected by the operator. Observed use in malvertising campaigns and selective targeting behavior indicate a criminal distribution service focused on efficient payload delivery and evasion of broad exposure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The latest version of this exploit kit, analyzed by researcher nao_sec in September, targets the CVE-2018-15982 (Flash Player) and the CVE-2018-8174 (Microsoft Internet Explorer VBScript Engine) vulnerabilities to infect visitors of attacker-controlled sites with malware. | The Windows version is being pushed through malvertising with the help of the Fallout Exploit Kit while the Linux payload is dropped via a yet unknown delivery system.
The latest version of this exploit kit, analyzed by researcher nao_sec in September, targets the CVE-2018-15982 (Flash Player) and the CVE-2018-8174 (Microsoft Internet Explorer VBScript Engine) vulnerabilities to infect visitors of attacker-controlled sites with malware. | The Windows version is being pushed through malvertising with the help of the Fallout Exploit Kit while the Linux payload is dropped via a yet unknown delivery system.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Exploit kit previously used by PseudoGate before switching to Spelevo.
An exploit kit used to deliver the Windows variant of ACBackdoor via malvertising by exploiting browser-related vulnerabilities.
Fallout Exploit Kit was used in the malvertising chain to redirect selected victims and deliver Vidar.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.