Paper: The journey and evolution of God Mode in 2016: CVE-2016-0189

Posted by   Martijn Grooten on   Jan 31, 2017

While avoiding the use of Flash is good advice for helping to fend off exploit kits, some of the vulnerabilities exploited by these kits actually target the browsers themselves. An important example of this is CVE-2016-0189, which affects Microsoft's Internet Explorer browser versions 9 through 11.

First discovered in the wild in targeted attacks in South Korea, the vulnerability was patched by Microsoft in May 2016 and started being used in exploit kits not long thereafter. It proved to be one of the most popular vulnerabilities for exploit kits in 2016.

God-Mode-Fig8.jpg

Today, we publish a paper (HTML and PDF) by FireEye researchers Ankit Anubhav and Manish Sardiwal, who thoroughly analyse this 'God Mode' vulnerability and explain what made it so popular in the cybercriminal ecosystem. Though this particular vulnerability may be on its last legs, it provides some important lessons, not just technically but also when it comes to understanding cybercrime.

If you have some research you'd like to share with the security community, we'd love to hear from you. Why not submit a paper for publication in Virus Bulletin or submit a proposal for VB2017.

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

VB2017: What is happening in the threat landscape and what are we doing against it? Submit a proposal in the VB2017 CFP!

Have you analysed a new online threat? Do you know a new way to defend against such threats? Then submit an abstract in the CFP for VB2017!

VB2016 paper: APT reports and OPSEC evolution, or: these are not the APT reports you are looking for

APT reports are great for gaining an understanding of how advanced attack groups operate - however, they can also provide free QA for the threat actors. Today, we publish a VB2016 paper by Gadi Evron (Cymmetria) and Inbar Raz (Perimeter X), who…

Security for your ears: recommended infosec podcasts

Industry veteran Mikko Hyppönen recently urged would-be security researchers to ditch their favourite pop music and listen to security podcasts on their commute to work instead. Virus Bulletin Editor Martijn Grooten shares his favourite security…

VB2016 video: Getting duped: piggybacking on webcam streams for surreptitious recordings

In a presentation at VB2016, Patrick Wardle, Director of Research at Synack, discussed the possibilities of Mac malware recording the user via the webcam. Today, we publish the video of Patrick's presentation.

We shouldn't forget those most vulnerable in our digital world

Virus Bulletin Editor Martijn Grooten calls for the security community not to forget those most vulnerable in the digital world, including political activists living under oppressive regimes, and victims of abuse.