Skip to main content

APT 28 DealersChoice Flash Exploit

DealersChoice is an exploit used by the Russian advanced persistent threat group APT28 (also known as FancyBear and Sofacy) that takes advantage of a vulnerability in older versions of Adobe Flash.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

DealersChoice is an exploit used by the Russian advanced persistent threat group APT28 (also known as FancyBear and Sofacy) that takes advantage of a vulnerability in older versions of Adobe Flash.

Affected platforms

The following platforms are known to be affected:

Threat details

DealersChoice uses Microsoft Word documents with Adobe Flash objects in them which when opened will attempt to connect to a command and control (C2) server to download additional Flash objects and a final payload. The Flash objects appear as small black dots on the third page of the document, making it difficult for the user to notice it. DealersChoice will run when this page is viewed by the user. This technique lets the objects avoid sandboxing, however it does require a number of interactions with the C2 Server to be successfully exploited.

At the time of publication the final payload remains uncertain but APT28 is known to use the Seduploader trojan.


Remediation steps

Type Step
  • Newer Adobe Flash versions are not vulnerable to DealersChoice exploitation. Users should update immediately.

Last edited: 17 February 2020 12:38 pm