Underminer is an exploit kit active since at least late 2017 and publicly identified in 2018. It has been used primarily in drive-by compromise campaigns, with activity concentrated in parts of Asia, especially Japan, Taiwan, and South Korea. Underminer has been associated with the delivery of a bootkit for persistence followed by the Hidden Bee cryptocurrency-mining malware, and later activity also showed it adapting exploit chains for Chromium in addition to its more traditional Internet Explorer and Adobe Flash exploitation.
Underminer operates as a web-based exploitation framework that profiles visiting systems and attempts browser-based exploitation to gain code execution. Observed campaigns used known vulnerabilities in Internet Explorer, Adobe Flash Player, and Chromium, including older Flash and IE flaws as well as later Chromium exploit chains paired with Windows privilege-escalation vulnerabilities. Reporting indicates its Internet Explorer-based chains were generally more successful than its Chromium-targeting efforts, likely because rapid browser patch adoption reduced the viable victim pool.
The kit has been linked to malvertising-style and drive-by delivery patterns typical of exploit kits. In documented campaigns, Underminer delivered a bootkit first to establish persistence on compromised Windows systems and then deployed Hidden Bee, a coinminer. It has also been observed using encrypted TCP tunnels as part of payload delivery. By combining browser exploitation, privilege escalation, and persistent malware deployment, Underminer functioned as a flexible delivery platform for follow-on malware rather than as the final payload itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
About a month later, we found that the Underminer exploit kit followed suit and developed an exploit for the same Chromium vulnerability.
This new exploit kit (EK) has been named Underminer ... active mainly in Asian countries ... spreading bootkits and cryptocurrency-mining (coinminer) malware.
About a month later, we found that the Underminer exploit kit followed suit and developed an exploit for the same Chromium vulnerability.
About a month later, we found that the Underminer exploit kit followed suit and developed an exploit for the same Chromium vulnerability.
This new exploit kit (EK) has been named Underminer ... active mainly in Asian countries ... spreading bootkits and cryptocurrency-mining (coinminer) malware.
Underminer is an Exploit Kit that appeared in 2018... It is used to deliver its unique malware called Hidden Bee.
About a month later, we found that the Underminer exploit kit followed suit and developed an exploit for the same Chromium vulnerability.
This new exploit kit (EK) has been named Underminer ... active mainly in Asian countries ... spreading bootkits and cryptocurrency-mining (coinminer) malware.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Browser exploit kit that developed a Chromium exploit chain and continued using it, though its traditional Internet Explorer exploit chains were reportedly more successful. In this content it uses CVE-2021-21224 with Windows privilege-escalation vulnerabilities.
Distinctive exploit kit described as difficult to analyze, used in periodic campaigns to deliver Hidden Bee malware.
An exploit kit active primarily in Asian countries that uses known browser/Flash exploits to infect users, then deploys a bootkit for persistence followed by coinminer malware via encrypted TCP tunnels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.