The decline of exploit kit activity—particularly from well-known exploit kits like Magnitude, Nuclear, Neutrino, and Rig during the latter half of 2016—doesn’t mean exploit kits are throwing in the towel just yet. This is the case with Astrum (also known as Stagano), an old and seemingly reticent exploit kit we observed to have been updated multiple times as of late.
Astrum’s recent activities feature several upgrades and shows how it's starting to move away from the more established malware mentioned above. It appears these changes were done to lay the groundwork for future campaigns, and possibly to broaden its use. With a modus operandi that deters analysis and forensics by abusing the Diffie-Hellman key exchange, it appears Astrum is throwing down the gauntlet.
Post from: Trendlabs Security Intelligence Blog - by Trend Micro
Will Astrum Fill the Vacuum in the Exploit Kit Landscape?
CSO Webinar: Email Fraud - Why you can't trust your emails anymore
CSO Perspectives Roadshow Interview - Silas Barnes, Group Chief Information Security Officer, Virgin Australia Group
CSO Perspectives Roadshow 2017 Showreel
CSO Perspectives Roadshow Interview - Jeff Lanza, Retired FBI Agent (USA)
CSO Perspectives Roadshow Interview - Mark Loveless "Simple Nomad" Senior Security Researcher at Duo Security