Multiple exploit kits remained active despite the broader decline of the exploit-kit ecosystem, using malvertising, compromised sites, and traffic distribution systems to drive victims to landing pages that exploited legacy Internet Explorer and Adobe Flash Player vulnerabilities. Reports identified RIG, Spelevo, PurpleFox, Underminer, Bottle, Magnitude, Angler, and GreenFlash Sundown abusing flaws including CVE-2021-26411, CVE-2020-1380, CVE-2018-8174, CVE-2018-15982, CVE-2018-4878, CVE-2016-0189, and CVE-2015-0311. Researchers said continued Internet Explorer use, unsupported Flash installations, and region-specific targeting kept drive-by download attacks viable, particularly across Japan, South Korea, Taiwan, Hong Kong, Malaysia, and other parts of Asia.
The campaigns delivered a wide range of malware families, showing that exploit kits were still an effective access vector for both cybercrime and broader malware operations. Spelevo was tied to the Japanese PseudoGate campaign distributing Ursnif, SmokeLoader, Ramnit, Kronos, and Zloader; RIG was seen pushing Pitou.B and ransomware such as CryptoLuck and Revenge; Magnitude delivered Magniber ransomware; Underminer deployed a bootkit and coinminer; GreenFlash Sundown delivered Hermes ransomware; Angler installed the Bedep trojan; and PurpleFox was linked to DirtyMoe cryptojacking and DDoS malware. The reporting underscored that unpatched or unsupported browsers and plugins continued to expose organizations to silent compromise, ransomware, banking trojans, spam bots, and cryptomining infections.

Pull IOCs and campaign context straight into your stack.
32 events from the most recent confirmed update back to the earliest known activity.
Magnitude exploit kit activity was reported in April 2021, including use of CVE-2021-26411.
Underminer exploit kit reappeared in April 2021 after being silent since November 2020.
Bottle exploit kit returned in April 2021 and was observed exploiting both CVE-2020-1380 and CVE-2021-26411 while targeting Japan.
PurpleFox exploit kit started exploiting CVE-2021-26411 in April 2021 to deliver PurpleFox malware.
RIG exploit kit started exploiting Internet Explorer vulnerability CVE-2021-26411 in April 2021.
Drive-by download attacks using exploit kits were still being observed in April 2021, with six kits active: RIG, Spelevo, PurpleFox, Underminer, Bottle, and Magnitude.
Researchers analyzed PseudoGate traffic observed in late February 2021, documenting a Keitaro TDS redirection chain leading to Spelevo exploitation of CVE-2018-15982 and delivery of banking trojans.
PseudoGate began using the Spelevo exploit kit instead of Fallout around December 2020.
A malware infection observed on June 24, 2019 showed makemoneyeasywith[.]me redirecting victims to a RIG exploit kit landing page, which served a Flash exploit and then delivered the Pitou.B Trojan.
Indicators showing makemoneyeasywith[.]me redirecting to RIG exploit kit were reported as early as June 21, 2019.
The domain makemoneyeasywith[.]me, used as a gate in a RIG exploit kit malvertising campaign, was registered.
Spelevo exploit kit appeared in 2019 and later remained one of the most active exploit kits observed in 2021.
In April 2018, Magnitude briefly distributed GandCrab ransomware after adopting the Flash zero-day CVE-2018-4878.
Telemetry recorded the first observed hit in a South Korea-focused campaign using GreenFlash Sundown exploit kit and CVE-2018-4878 to deliver Hermes ransomware 2.1.
PseudoGate was reported in 2018 as a Japanese-language drive-by download campaign delivering banking trojans.
In October 2017, the Magnitude operator switched to distributing Magniber ransomware, initially with campaigns heavily restricted to South Korea.
Researchers linked signs of Underminer exploit kit activity back to late 2017, before its public naming in 2018.
DirtyMoe's first significant observed activity occurred in 2017, according to Avast's historical overview of the malware family.
Magnitude exploit kit previously delivered Cerber ransomware through its Magnigate filtering gate in 2017.
The RIG exploit kit had been active since around 2014, according to later reporting on exploit kit activity.
The Magnitude exploit kit was active by 2013, making it one of the longest-running browser exploitation toolkits still in use.
Avast published an overview of DirtyMoe describing PurpleFox as the commonly used exploit kit for distributing the malware and estimating roughly 100,000 active infections.
By mid-2018, Magniber campaigns delivered by Magnitude had expanded beyond South Korea, with exploit attempts observed in Malaysia and infections reported in Taiwan and Hong Kong.
Researchers publicly reported a new exploit kit named Underminer that was distributing a bootkit followed by Hidden Mellifera or Hidden Bee coin-mining malware, with traffic concentrated in Japan, Taiwan, and South Korea.
Trend Micro said it found the first clues of the Underminer exploit kit's existence around July 17.
MDNC discovered that GreenFlash Sundown exploit kit was using Flash zero-day CVE-2018-4878 to distribute Hermes ransomware.
At the end of January, KrCERT published news about targeted attacks using Flash Player zero-day CVE-2018-4878.
Broad Analysis and Brad Duncan observed the Revenge ransomware variant, a CryptoMix/CryptFile2 offshoot, being distributed through hacked websites using the RIG exploit kit.
Proofpoint researcher Kafeine discovered the CryptoLuck ransomware family being distributed through the RIG-E exploit kit, including malvertising in the adult website space.
Adobe remediated CVE-2015-0311 by releasing Flash Player version 16.0.0.296.
Adobe released security advisory APSA15-01 in response to the in-the-wild exploitation of Flash zero-day CVE-2015-0311.
A malvertising campaign redirected users from legitimate sites to Angler Exploit Kit landing pages that actively exploited Adobe Flash zero-day CVE-2015-0311 and installed the Bedep Trojan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
10 references tracked. Mallory keeps watching after this page renders.
decoded.avast.io
Open sourcenao-sec.org
Open sourceinsight-jp.nttsecurity.com
Open sourceisc.sans.edu
Open sourcemalwarebytes.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.