Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a 2014 Angler exploit-kit attack, the payload was Necurs, a Trojan that was decrypted in memory and injected into a running web-browser process as a new thread instead of being saved as a conventional executable. That approach left less evidence on disk and could evade security checks focused on downloaded files, but it did not make the infection invisible or harmless.

How did Angler inject malware into a process?

SecurityWeek reported on September 3, 2014 that Angler used process injection to run Necurs inside an existing browser process. The attack decrypted an encrypted payload using XOR, then loaded the code into a process such as iexplore.exe as a new thread. The payload ran from memory rather than launching as a newly downloaded program.

That distinction matters: a file scanner looking for a suspicious executable on disk might have less to inspect, while the malicious code could still execute inside a process that appeared to belong to the browser. The technique could also frustrate some host-based intrusion-prevention checks. It did not guarantee that antivirus or other security tools would miss the activity; detection depended on what the tools monitored and how the attack was delivered.

SecurityWeek noted that the malware could remain active in memory after the user closed the browser. Closing a browser window is not necessarily the same as terminating every related process. In the report, the malware’s memory-resident activity ended when the injected process was terminated or the machine was restarted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What was the Angler infection chain?

Angler was an exploit kit: a delivery platform that used web traffic and software vulnerabilities to install malware. Malwarebytes describes common entry points as malicious advertising and compromised websites. A typical chain looked like this:

  1. Exposure: A user visited a compromised site or encountered a malvertising placement.
  2. Redirection: The page sent the browser, sometimes through an inconspicuous iframe, to an Angler landing page.
  3. Exploit attempt: Angler tested for vulnerable software and attempted to exploit it. Flash Player and Internet Explorer were among the targets, though the specific exploit depended on the campaign and software version.
  4. Payload execution: If exploitation succeeded, Angler delivered malware. Some campaigns wrote a payload to disk; the 2014 Necurs incident used direct injection into memory.

Microsoft’s Exploit:SWF/Axpergle entry associates Angler-linked Flash files with CVE-2014-8439, CVE-2015-0310, CVE-2015-0311 and CVE-2015-0313. Those identifiers do not mean every Angler infection used every exploit: the vulnerable application, its version and the campaign determined which exploit could work.

Why did memory injection matter?

A conventional infection that saves an executable gives defenders a file to scan, quarantine or examine. With process injection, code can run from memory without leaving the same kind of payload file behind. That reduces one source of forensic evidence and can bypass controls that rely heavily on inspecting downloaded files.

Memory execution shifts the defensive challenge rather than eliminating it. Security tools may also look for suspicious memory allocation, remote-thread creation, unexpected behavior inside a browser, exploit activity or a malicious redirect chain. The Angler incident is a historical example of why file-only inspection is incomplete; it is not evidence that all antivirus products failed to detect the attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did Angler deliver, and how large was its impact?

Necurs was the payload in the 2014 incident, not another name for Angler. Necurs could disable security products and download additional threats. Angler itself was a delivery platform and was associated over time with other malware, including Bedep, ransomware and additional payloads.

Reported figure Scope and source
42% of infections Malwarebytes and GeoEdge campaign data from 2015, published in 2016; the figure describes that dataset, not current infection prevalence.
19 cents per 1,000 impressions Malwarebytes and GeoEdge data on a 2015 campaign, published in 2016; this is a campaign-specific advertising cost, not a general or current rate.
More than $30 million in annual revenue Cisco Talos’s 2015 Angler analysis; an estimate for that period, not a current revenue figure.
60% of exploit-kit traffic Proofpoint’s data covering 2015 through the first quarter of 2016, published in its Q2 2016 threat report; this is a historical share for that measurement period.

Is Angler still active?

Malwarebytes says Angler became inactive in June 2016. Proofpoint’s Q2 2016 threat report also described Angler going dark and attackers shifting toward Neutrino. These historical reports do not establish current Angler infrastructure, so Angler is best understood as a major exploit kit from that period rather than a currently confirmed threat.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can defenders reduce the risk of similar attacks?

The useful lessons apply to exploit-driven malware generally, not as a claim that a specific current product detects the 2014 Necurs sample.

  • Patch browsers and plugins: Keep browser components and other internet-facing software updated, and remove unsupported plugins. Patching reduces exposure to known vulnerabilities that exploit kits may target.
  • Use exploit mitigation: Security controls that mitigate browser and application exploits can add protection beyond file scanning. Malwarebytes reported that its Anti-Exploit users were protected against an Angler malvertising attack; that is a report about that attack, not a guarantee about other products or current threats.
  • Monitor process behavior: Endpoint monitoring should account for suspicious memory allocation, remote-thread activity and unusual behavior within trusted applications, rather than treating a familiar process name as proof of safety.
  • Limit malicious web delivery: Browser protections and network controls that identify harmful redirects, injected scripts and malvertising can help disrupt the chain before an exploit page runs.
  • Preserve evidence beyond the disk: Incident response should consider volatile memory and process activity as well as files. A missing payload file does not establish that no code ran.

Angler’s significance was the combination of web-based exploit delivery and execution inside a legitimate process. It showed why defending against malware requires attention to vulnerabilities, redirects and runtime behavior—not just the files left behind.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.