November 3, 2016 By Larry Loeb 2 min read

Researchers from Cisco Talos reported an uptick in the use of second-tier exploit kits (EKs) for the delivery of malware.

Nuclear, Angler and Neutrino EKs — the main players in the arena — have all scaled back their operations, leaving a power void in the space. This enabled other contenders, such as the Sundown exploit kit, to make a run at the EK throne.

Introducing Sundown Exploit Kit

After a deeper look at Sundown, Talos researchers were surprised by what they found. To start, Sundown operates on a relatively small infrastructure footprint. At the same time, it runs one of the largest domain shadowing implementations Talos had ever seen. This is truly an asymmetrical approach.

While just a few IPs — researchers found only 10 — were directly linked to a campaign, Talos discovered that Sundown’s registrant accounts used more than 80,000 malicious subdomains that were associated with over 500 domains. The sheer number of domains renders traditional blacklisting solutions pretty much useless.

In addition, Sundown efficiently recycles the subdomains after use. This helps it avoid possible detection by not leaving a trail of visible past operations behind.

The Big Takeaway

Sundown is similar to other recent exploit kits in the way it operates. It features a landing page and an exploit page that contains a payload. The compromised landing page includes an iframe.

That iframe points to some location on the page that renders off screen, redirecting the browser to the exploit page. This exploit page evaluates the incoming victim for vulnerabilities before it delivers a malicious payload.

Sundown has quirks, to be sure. For one thing, it reuses exploits, and it also uses wildcard domains in its shadowing.

Lastly, the developers do not seem sophisticated enough to understand why they might want to hide the EK from sight. The colorful logo Sundown displays indicates the authors want to be seen and well-known.

“The big takeaway,” Talos researcher Nick Biasini told Threatpost, is that “Sundown is a much larger threat than people realize.”

More from

Evolving red teaming for AI environments

2 min read - As AI becomes more ingrained in businesses and daily life, the importance of security grows more paramount. In fact, according to the IBM Institute for Business Value, 96% of executives say adopting generative AI (GenAI) makes a security breach likely in their organization in the next three years. Whether it’s a model performing unintended actions, generating misleading or harmful responses or revealing sensitive information, in the AI era security can no longer be an afterthought to innovation.AI red teaming is emerging…

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today