Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Exploit kit</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Exploit_kit"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Exploit_kit rootpage-Exploit_kit skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Exploit kit</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p class="mw-empty-elt">
</p><p>An <b>exploit kit</b> is a tool used for automatically managing and deploying <a href="Exploit_(computer_security)" title="Exploit (computer security)">exploits</a> against a target computer. Exploit kits allow attackers to deliver <a href="Malware" title="Malware">malware</a> without having advanced knowledge of the exploits being used. <a href="Browser_exploit" class="mw-redirect" title="Browser exploit">Browser exploits</a> are typically used, although they may also include exploits targeting common software, such as <a href="Adobe_Reader" class="mw-redirect" title="Adobe Reader">Adobe Reader</a>, or the <a href="Operating_system" title="Operating system">operating system</a> itself. Most kits are written in <a href="PHP" title="PHP">PHP</a>.<sup id="cite_ref-mb-tools_1-0" class="reference"><a href="#cite_note-mb-tools-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>Exploit kits are often sold on the <a href="Black_market" title="Black market">black market</a>, both as standalone kits, and as a <a href="Software_as_a_service" title="Software as a service">service</a>.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="History">History</h2></div>
<p>Some of the first exploit kits were <a href="WebAttacker" class="mw-redirect" title="WebAttacker">WebAttacker</a> and <a href="MPack_(software)" title="MPack (software)">MPack</a>, both created in 2006. They were sold on black markets, enabling attackers to use exploits without advanced knowledge of <a href="Computer_security" title="Computer security">computer security</a>.<sup id="cite_ref-Evolution_of_Exploit_Kits_2-0" class="reference"><a href="#cite_note-Evolution_of_Exploit_Kits-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-Markets_for_Cybercrime_Tools_and_Stolen_Data:_Hackers'_Bazaar_3-0" class="reference"><a href="#cite_note-Markets_for_Cybercrime_Tools_and_Stolen_Data:_Hackers'_Bazaar-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p><p>The <a href="Blackhole_exploit_kit" title="Blackhole exploit kit">Blackhole exploit kit</a> was released in 2010, and could either be purchased outright, or rented for a fee.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Malwarebytes stated that Blackhole was the primary method of delivering malware in 2012 and much of 2013.<sup id="cite_ref-mwb-threat-2013_5-0" class="reference"><a href="#cite_note-mwb-threat-2013-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> After the arrest of the authors in late 2013, use of the kit sharply declined.<sup id="cite_ref-mwb-threat-2013_5-1" class="reference"><a href="#cite_note-mwb-threat-2013-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>Neutrino was first detected in 2012,<sup id="cite_ref-cyware-neutrino_8-0" class="reference"><a href="#cite_note-cyware-neutrino-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> and was used in a number of <a href="Ransomware" title="Ransomware">ransomware</a> campaigns. It exploited vulnerabilities in <a href="Adobe_Reader" class="mw-redirect" title="Adobe Reader">Adobe Reader</a>, the <a href="Java_Runtime_Environment" class="mw-redirect" title="Java Runtime Environment">Java Runtime Environment</a>, and <a href="Adobe_Flash" title="Adobe Flash">Adobe Flash</a>.<sup id="cite_ref-mwb-neutrino_9-0" class="reference"><a href="#cite_note-mwb-neutrino-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> Following a joint-operation between <a href="Cisco_Talos" title="Cisco Talos">Cisco Talos</a> and <a href="GoDaddy" title="GoDaddy">GoDaddy</a> to disrupt a Neutrino <a href="Malvertising" title="Malvertising">malvertising</a> campaign,<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> the authors stopped selling the kit, deciding to only provide support and updates to previous clients. Despite this, development of the kit continued, and new exploits were added.<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> As of April 2017, Neutrino activity ceased.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> On June 15, 2017, <a href="F-Secure" title="F-Secure">F-Secure</a> tweeted "R.I.P. Neutrino exploit kit. We'll miss you (not)." with a graph showing the complete decline of Neutrino detections.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p><p>From 2017 onwards, the usage of exploit kits has dwindled. There are a number of factors which may have caused this, including arrests of cybercriminals, improvements in security making exploitation harder, and cybercriminals turning to other method of malware delivery, such as <a href="Microsoft_Office" title="Microsoft Office">Microsoft Office</a> <a href="Macro_virus" title="Macro virus">macros</a> and <a href="Social_engineering_(security)" title="Social engineering (security)">social engineering</a>.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</p><p>There are many systems that work to protect against attacks from exploit kits. These include <a href="Antivirus_software" title="Antivirus software">gateway anti-virus</a>, intrusion prevention, and anti-spyware. There are also ways for subscribers to receive these prevention systems on a continuous basis, which helps them to better defend themselves against attacks.<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Overview">Overview</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Exploitation_process">Exploitation process</h3></div>
<p>The general process of exploitation by an exploit kit is as follows:
</p>
<ol><li>The victim navigates to a website infected by an exploit kit. Links to infected pages can be spread via <a href="Spamming" title="Spamming">spam</a>, <a href="Malvertising" title="Malvertising">malvertising</a>, or by compromising legitimate sites.</li>
<li>The victim is redirected to the landing page of the exploit kit.</li>
<li>The exploit kit determines which vulnerabilities are present, and which exploit to deploy against the target.</li>
<li>The exploit is deployed. If successful, a payload of the attacker's choosing (i.e. malware) can then be deployed on the target.<sup id="cite_ref-mb-tools_1-1" class="reference"><a href="#cite_note-mb-tools-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup></li></ol>
<div class="mw-heading mw-heading3"><h3 id="Features">Features</h3></div>
<p>Exploit kits employ a variety of <a href="Evasion_(network_security)" title="Evasion (network security)">evasion techniques</a> to avoid detection. Some of these techniques include <a href="Obfuscation_(software)" title="Obfuscation (software)">obfuscating</a> the code,<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> and using <a href="Device_fingerprint" title="Device fingerprint">fingerprinting</a> to ensure malicious content is only delivered to likely targets.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-mb-tools_1-2" class="reference"><a href="#cite_note-mb-tools-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>Modern exploit kits include features such as <a href="Web_application" title="Web application">web interfaces</a> and statistics, tracking the number of visitors and victims.<sup id="cite_ref-mb-tools_1-3" class="reference"><a href="#cite_note-mb-tools-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1184024115">
/* start https://en.wikipedia.org/ */


.mw-parser-output .div-col{margin-top:0.3em;column-width:30em}.mw-parser-output .div-col-small{font-size:90%}.mw-parser-output .div-col-rules{column-rule:1px solid #aaa}.mw-parser-output .div-col dl,.mw-parser-output .div-col ol,.mw-parser-output .div-col ul{margin-top:0}.mw-parser-output .div-col li,.mw-parser-output .div-col dd{page-break-inside:avoid;break-inside:avoid-column}


/* end https://en.wikipedia.org/ */
</style><div class="div-col" style="column-width: 30em;">
<ul><li><a href="Dendroid_(Malware)" class="mw-redirect" title="Dendroid (Malware)">Dendroid (Malware)</a></li>
<li><a href="Trojan_horse_(computing)" title="Trojan horse (computing)">Trojan horse (computing)</a></li>
<li><a href="Spyware" title="Spyware">Spyware</a></li>
<li><a href="Botnet" title="Botnet">Botnet</a></li>
<li><a href="Computer_virus" title="Computer virus">Computer virus</a></li>
<li><a href="Backdoor_(computing)" title="Backdoor (computing)">Backdoor (computing)</a></li>
<li><a href="Tiny_Banker_Trojan" title="Tiny Banker Trojan">Tiny Banker Trojan</a></li>
<li><a href="Zeus_(malware)" title="Zeus (malware)">Zeus (malware)</a></li>
<li><a href="Gameover_ZeuS" title="Gameover ZeuS">Gameover ZeuS</a></li></ul></div>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-mb-tools-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-mb-tools_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-mb-tools_1-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-mb-tools_1-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-mb-tools_1-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFCannell2013" class="citation web cs1">Cannell, Joshua (11 February 2013). <a rel="nofollow" class="external text" href="https://blog.malwarebytes.com/cybercrime/2013/02/tools-of-the-trade-exploit-kits/">"Tools of the Trade: Exploit Kits"</a>. <i>Malwarebytes Labs</i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-Evolution_of_Exploit_Kits-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-Evolution_of_Exploit_Kits_2-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFChenLi" class="citation web cs1">Chen, Joseph; Li, Brooks. <a rel="nofollow" class="external text" href="https://documents.trendmicro.com/assets/wp/wp-evolution-of-exploit-kits.pdf">"Evolution of Exploit Kits"</a> <span class="cs1-format">(PDF)</span>. <a href="Trend_Micro" title="Trend Micro">Trend Micro</a><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-Markets_for_Cybercrime_Tools_and_Stolen_Data:_Hackers'_Bazaar-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-Markets_for_Cybercrime_Tools_and_Stolen_Data:_Hackers'_Bazaar_3-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.rand.org/content/dam/rand/pubs/research_reports/RR600/RR610/RAND_RR610.pdf">"Markets for Cybercrime Tools and Stolen Data"</a> <span class="cs1-format">(PDF)</span>. <a href="RAND_Corporation" title="RAND Corporation">RAND Corporation</a>. 2014.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.bbc.com/news/technology-24456988">"Blackhole malware exploit kit suspect arrested"</a>. <i>BBC News</i>. 9 October 2013<span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-mwb-threat-2013-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-mwb-threat-2013_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-mwb-threat-2013_5-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFKujawa2013" class="citation web cs1">Kujawa, Adam (4 December 2013). <a rel="nofollow" class="external text" href="https://blog.malwarebytes.com/security-world/2013/12/malwarebytes-2013-threat-report/">"Malwarebytes 2013 Threat Report"</a>. <i>Malwarebytes Labs</i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><b><a href="#cite_ref-6">^</a></b></span> <span class="reference-text"><cite id="CITEREFZorabedian2013" class="citation web cs1">Zorabedian, John (9 October 2013). <a rel="nofollow" class="external text" href="https://news.sophos.com/en-us/2013/10/09/is-the-blackhole-exploit-kit-finished/">"Is the Blackhole exploit kit finished?"</a>. <i>Sophos News</i><span class="reference-accessdate">. Retrieved <span class="nowrap">3 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-7">^</a></b></span> <span class="reference-text"><cite id="CITEREFFisher2013" class="citation web cs1">Fisher, Dennis (26 November 2013). <a rel="nofollow" class="external text" href="https://threatpost.com/blackhole-and-cool-exploit-kits-nearly-extinct/103034/">"Blackhole and Cool Exploit Kits Nearly Extinct"</a>. <i>threatpost.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">3 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-cyware-neutrino-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-cyware-neutrino_8-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://cyware.com/news/neutrino-exploit-kit-a-walk-through-into-the-exploit-kits-campaigns-distributing-various-ransomware-cb14cdb8">"Neutrino Exploit kit: A walk-through into the exploit kit's campaigns distributing various ransomware"</a>. <i>Cyware Labs</i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-mwb-neutrino-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-mwb-neutrino_9-0">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://blog.malwarebytes.com/threats/neutrino/">"Neutrino"</a>. <i>Malwarebytes Labs</i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://threatpost.com/malvertising-campaign-pushing-neutrino-exploit-kit-shut-down/120322/">"Malvertising Campaign Pushing Neutrino Exploit Kit Shut Down"</a>. <i>threatpost.com</i>. September 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.bleepingcomputer.com/news/security/former-major-player-neutrino-exploit-kit-has-gone-dark/">"Former Major Player Neutrino Exploit Kit Has Gone Dark"</a>. <i><a href="Bleeping_Computer" title="Bleeping Computer">Bleeping Computer</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFSchwartz2017" class="citation web cs1">Schwartz, Mathew (15 June 2017). <a rel="nofollow" class="external text" href="https://www.bankinfosecurity.com/neutrino-exploit-kit-no-signs-life-a-9999">"Neutrino Exploit Kit: No Signs of Life"</a>. <i>www.bankinfosecurity.com</i><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite id="CITEREFF-Secure2017" class="citation web cs1"><a href="F-Secure" title="F-Secure">F-Secure</a> [@FSLabs] (15 June 2017). <a rel="nofollow" class="external text" href="https://x.com/FSLabs/status/875275005625597953">"R.I.P. Neutrino exploit kit. We'll miss you (not)"</a> (<a href="Tweet_(social_media)" title="Tweet (social media)">Tweet</a>) – via <a href="Twitter" title="Twitter">Twitter</a>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://threatpost.com/where-have-all-the-exploit-kits-gone/124241/">"Where Have All The Exploit Kits Gone?"</a>. <i>threatpost.com</i>. 15 March 2017<span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite id="CITEREFMalecki2013" class="citation journal cs1">Malecki, Florian (June 2013). <span class="id-lock-subscription" title="Paid subscription required"><a rel="nofollow" class="external text" href="https://linkinghub.elsevier.com/retrieve/pii/S1361372313700563">"Defending your business from exploit kits"</a></span>. <i>Computer Fraud &amp; Security</i>. <b>2013</b> (6): <span class="nowrap">19–</span>20. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2FS1361-3723%2813%2970056-3">10.1016/S1361-3723(13)70056-3</a>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.trendmicro.com/vinfo/us/security/definition/exploit-kit">"exploit kit - Definition"</a>. <a href="Trend_Micro" title="Trend Micro">Trend Micro</a><span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-exploit-kits-improve-evasion-techniques/">"Exploit Kits Improve Evasion Techniques"</a>. <i>McAfee Blog</i>. 12 November 2014<span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://unit42.paloaltonetworks.com/angler-exploit-kit-continues-to-evade-detection-over-90000-websites-compromised/">"Angler Exploit Kit Continues to Evade Detection: Over 90,000 Websites Compromised"</a>. <i>Unit42</i>. 11 January 2016<span class="reference-accessdate">. Retrieved <span class="nowrap">8 April</span> 2022</span>.</cite></span>
</li>
</ol></div></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-05-26" href="https://en.wikipedia.org/wiki/?title=Exploit_kit&amp;oldid=1292260615">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>