RIG Exploit Kit is a long-running exploit kit active since approximately 2014 that delivers malware through drive-by compromise chains, most notably malvertising and redirect-based traffic funnels. It primarily targets Windows systems via Internet Explorer and historically abused browser and Adobe Flash Player vulnerabilities, including CVE-2018-15982, CVE-2019-0752, CVE-2020-0674, and CVE-2021-26411. Observed campaigns used decoy pages, cloaking, fingerprinting, and HTTP redirection to steer selected victims to exploit landing pages, after which successful exploitation resulted in payload delivery.
RIG has been used as a malware distribution service for multiple crimeware families. Reported payloads include Raccoon Stealer, Panda Banker, Nemty ransomware, Phorpiex-related malware, and DRIFTPIN. Campaigns associated with RIG have frequently relied on malvertising, including traffic from adult-content websites, and have targeted users still dependent on outdated Internet Explorer and Flash-based environments. By 2021, RIG remained one of the few exploit kits still active in the wild and had incorporated newer Internet Explorer exploits while simplifying some landing-page obfuscation compared with earlier generations.
RIG functions as an initial-access platform rather than a standalone payload family, enabling downstream credential theft, banking fraud, ransomware deployment, and broader post-compromise activity by customer malware operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
RIG is an Exploit Kit that has been active since around 2014... RIG started abusing CVE-2021-26411 in April 2021 and are still incorporating changes.
RIG is an Exploit Kit that has been active since around 2014... RIG started abusing CVE-2021-26411 in April 2021 and are still incorporating changes.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The landing page is a large file and consists of five scripts. The top section, through some misdirection and obfuscation, assigns a value of “body” to the “vx” variable... All it’s doing is building up decimal values... then converted to ASCII and appended to the body element.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rig exploit kit is mentioned as a previously used delivery mechanism that Purple Fox later abandoned in favor of PowerShell-based fileless execution.
Exploit kit used in drive-by download attacks, historically active since 2014 and observed exploiting Internet Explorer vulnerabilities to deliver malware payloads.
An exploit kit mentioned as the earlier delivery mechanism for Purple Fox before Purple Fox developed its own exploit kit.
Exploit kit used in the malvertising chain to deliver Raccoon Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.