The creators of the Phoenix exploit kit have begun using obfuscation and other techniques to prevent security researchers and others from reverse-engineering the installation process for the kit. This tactic has become increasingly popular among attackers recently. Researchers have found a version of the kit that includes installation code that is completely obfuscated, making it more difficult for researchers to observe the. installation process and see how it works. The Phoenix exploit toolkit is one of a number of similar toolkits sold by various attack developers to attackers.
Source: https://threatpost.com/exploit-kits-employing-obfuscation-prevent-analysis-122910/74807/

