Cisco Talos reported strong operational links between the Angler Exploit Kit and the Bedep malware downloader, connecting landing pages, redirectors, Bedep DGA command-and-control domains, and payload infrastructure through shared registrant details, email accounts, domain patterns, and reused web content. The investigation, which began around exploitation tied to Adobe Flash zero-day CVE-2015-0310, found that Angler instances distributing Bedep were often separate from those directly serving ransomware, but infected hosts could later be funneled to other Angler infrastructure for additional payloads.
Traffic analysis from a pseudo-Darkleech campaign showed that compromised web content redirected victims to an Angler server at 185.118.66[.]154, where exploitation led to Bedep infection followed by CryptXXX ransomware on a normal host. Researchers also observed Bedep using anti-VM behavior: in virtualized environments it contacted 95.211.205[.]228, downloaded different malware, and did not deliver CryptXXX, while related activity included click-fraud traffic and execution of a dropped svchost.exe file identified as rundll32.exe to launch the CryptXXX DLL.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
On 2016-05-09, the observer again saw svchost.exe dropped in the same folder as the CryptXXX ransomware DLL. The report noted this CryptXXX behavior and its decryption instructions differed slightly from earlier samples.
On 2016-05-09, a pseudo-Darkleech campaign redirected victims to the Angler exploit kit at 185.118.66[.]154 using tilewrigbaieru.gt-racer[.]co[.]uk, leading to Bedep infection and CryptXXX ransomware on a normal host. The report also documented Bedep post-infection traffic, CryptXXX C2 over TCP 443, and separate click-fraud activity.
By 2016-05-02, the observer noted that only the CryptXXX ransomware DLL remained in the folder where svchost.exe had previously been seen. This documented a change in the post-infection file state.
On 2016-04-29, the observer saw a dropped svchost.exe file, identified as rundll32.exe, in the same folder as the CryptXXX ransomware DLL. The file was used to execute the CryptXXX payload.
Talos traced infrastructure used during the Adobe Flash zero-day CVE-2015-0310 campaign associated with Angler and found the early hosting domains were registered under yingw90@yahoo.com. Talos later linked that same registrant data to Bedep DGA command-and-control domains and related infrastructure.
Cisco Talos published research concluding that the Angler Exploit Kit and the Bedep malware downloader were at minimum closely related and likely shared infrastructure or operators. The analysis linked Angler landing pages, Bedep DGA C2 domains, redirectors, and payload delivery infrastructure through shared registrant data, email addresses, domain patterns, and reused webpages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
malware-traffic-analysis.net
Open sourceblog.talosintelligence.com
Open sourcemalware.dontneedcoffee.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.