#Erebus
Incident/Operation
2017-08-30 • WALKING IN YOUR ENEMY’S SHADOW: WHEN FOURTH-PARTY COLLECTION BECOMES ATTRIBUTION HELL
Operation Erebus was a May 2016 watering-hole campaign in which compromised websites delivered an exploit for an Adobe Flash Player vulnerability. The exploit had been taken from previously known samples associated with FinFisher delivery, with modified shellcode and a different payload location, and the activity initially lacked an obvious connection to a known malware family. Infrastructure and operational overlaps placed Erebus in a complex intersection of activity associated with ScarCruft and DarkHotel, supporting relationships to both clusters without assigning the campaign exclusively to either actor.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days