APT 28 DealersChoice Flash Exploit
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
DealersChoice uses Microsoft Word documents with Adobe Flash objects in them which when opened will attempt to connect to a command and control (C2) server to download additional Flash objects and a final payload. The Flash objects appear as small black dots on the third page of the document, making it difficult for the user to notice it. DealersChoice will run when this page is viewed by the user. This technique lets the objects avoid sandboxing, however it does require a number of interactions with the C2 Server to be successfully exploited.
At the time of publication the final payload remains uncertain but APT28 is known to use the Seduploader trojan.
Remediation steps
Last edited: 17 February 2020 12:38 pm