Threat Database Malware Infinity Exploit Kit

Infinity Exploit Kit

By GoldSparrow in Malware

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: May 29, 2014
Last Seen: January 3, 2021
OS(es) Affected: Windows

The Infinity Exploit Kit is an exploit kit that uses vulnerabilities in Mozilla Firefox, Internet Explorer and Opera to install threats on the victims' computers. Malware analysts have also reported that the Infinity Exploit Kit exploits known vulnerabilities in Web browser add-ons and platforms like Java and Adobe Flash to carry out its attacks. The Infinity Exploit Kit is used to compromise the victims' computers and may be associated with other threats. PC security analysts spotted the Infinity Exploit Kit being sold on underground markets, allowing third parties to use the Infinity Exploit Kit for $100 USD per day. It is not an exorbitant amount, considering the enormous amounts of money that may be made from threat attacks and online misleading tactics.

The Infinity Exploit Kit Will Find and Use Any Vulnerability to Install Threats on the PC

The Infinity Exploit Kit will exploit numerous vulnerabilities at the same time. Among the vulnerabilities exploited by the Infinity Exploit Kit are CVE-2013-2465, CVE-2013-2423, CVE-2013-1347, CVE-2014-0322, CVE-2014-1776 and CVE-2014-0502. The creators of the Infinity Exploit Kit update the Infinity Exploit Kit regularly, allowing the Infinity Exploit Kit to stay up-to-date to security patches and new vulnerabilities that are uncovered. The authors of the Infinity Exploit Kit are on the market for new vulnerabilities that may allow them to take one step ahead of their competitors.

Identifying the Source of the Infinity Exploit Kit Infection

The documentation and advertisements associated with the Infinity Exploit Kit are all in Russian. The threat author is known by his online pseudonyms 'iny' and 'pickness' and PC security researchers suspect that the Infinity Exploit Kit originates in Eastern Europe, in a Russian-speaking country. The Infinity Exploit Kit author has a high reputation among ill-minded persons and frequenters of underground forums. After the arrest of the creator of the Black Hole Exploit Kit, it is telling that the author of the Infinity Exploit Kit is highly secretive, and access to the Infinity Exploit Kit is highly restricted and usually only through private communications. Although most exploit kits that are used today are variants of the infamous Back Hole attack, new contenders like the Infinity Exploit Kit are starting to gain ground.


Most Viewed