Neutrino Exploit Kit Activity Slows Down to a Trickle

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
The exploit kit (EK) landscape appears to have lost another major player, with unconfirmed rumors that the Neutrino exploit kit has shut down, or at least moved to a private client without being available on the "for-hire" market.

French security researcher Kaffeine published today a message exchanged in the criminal underground. The text reads "we are closed. no new rents, no extends more," and is a Jabber message sent by the Neutrino EK author to another third-party.

The date of the message is September 9. Banners advertising the Neutrino exploit kit have disappeared from underground hacking forums around September 16.

Neutrino has been losing clients to RIG for the past month
Malicious traffic campaigns that redirected users to the Neutrino EK didn't stop all of a sudden after that message but slowly switched to the RIG exploit kit during the past month. Security firms like Malwarebytes, Heimdal Security, and Malware Traffic Analysis noted a slowdown in Neutrino activity this past month.

Kaffeine says that after October 1, except two campaigns, the Neutrino exploit kit is all but gone.

At the end of August, a joint Cisco and GoDaddy operation shut down a large number of malvertising campaigns running on the Neutrino EK.

The gang behind Neutrino either got spooked because their operation was tracked down or have lost a great deal of credibility in the underground market.

Based on the message Kaffeine discovered, it appears the first theory might be more realistic, with the Neutrino gang slowly retreating from the market, afraid they might get too exposed and then arrested.

Read more: http://news.softpedia.com/news/neutrino-exploit-kit-activity-slows-down-to-a-trickle-508861.shtml


Related: https://blog.malwarebytes.com/threa...7/a-look-into-some-rig-exploit-kit-campaigns/
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
I didn't vote for either as I think it may be going through a Re-Working of sorts ?
We have seen a few disappear only to resurface rebuffed and given new life.
Time will tell though.
Awesome Share Jack
 
L

LabZero

Mainly Neutrino is effective to launch targeted attacks on users using Java and without having to make big efforts as it is ready and easy to find.
If this kit will be off, among other reasons, I also think because of Java is not more used such as time ago.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Its definitely a normal scenario [shutdown], developing a form of threats are so easy; due to the fact that rapid tools can be easily accessible.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top