New project, named Shadowfall, was announced this week by RSA, in collaboration with Malwarebytes, Palo Alto Networks and Broad Analysis. RIG has been the top exploit kit since Angler was taken down, delivering both Cerber and CryptoMix ransomwares as well as the Smoke loader backdoor. This method occurs when attackers steal actual credentials from domain owners and then use them to create subdomains pointing to malicious servers. These servers hide in legitimate domains, making them unlikely to be blacklisted because of suspicion of malfeasance.”]
Source: https://securityintelligence.com/news/project-shadowfall-helps-tackle-rig-exploit-kit/