/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

RIG Exploit Kit 3.0 Used to Infect Over 1.3 Million Computers Worldwide

Version 3.0 of the notorious RIG exploit kit has been released.  Researchers at Trustwave have determined that the crimeware has already been used to infect more than 1.3 million devices from all over the world.

SecurityWeek Eduard Kovacs

Context & Ripple Effects

RIG is one of the crimeware-as-a-service staples of the mid-2010s drive-by ecosystem, and Trustwave's count shows how fast a kit refresh pays off: version 3.0 alone has already touched over 1.3 million machines worldwide. It slots into a supply chain that Cisco had mapped months earlier, when its researchers found 1,800 compromised domains serving a Flash zero day to visitors — the same model of renting web traffic into an infection pipeline that RIG productizes.

What makes the milestone worth watching is who ends up holding the infections: exploit kits are distribution infrastructure, and whatever payload gets swapped in — banking trojans or, increasingly, ransomware — inherits the reach. Later corpus findings show where that leads, from leaked NSA tooling becoming a go-to weapon (EternalBlue) to persistence layers that survive OS reinstalls.

First-order effects

  • Over 1.3 million device owners are already compromised by RIG 3.0 traffic, most without any indication beyond browser-level exploitation they never see.
  • Security teams tracking Trustwave's reporting now have a new kit fingerprint to hunt for, while the kit's operators gain a fresh revenue line selling access to the infected pool.

Second-order effects

  • Payload sellers — ransomware crews above all, given Trustwave's own finding that ransomware attacks quadrupled year-over-year by 2019 — get a cheaper on-ramp than running their own phishing operations.
  • Competing kit authors are pushed into an update arms race, since each browser and plugin patch devalues the previous version's exploit set — the dynamic behind McAfee later counting 100+ unique exploits weaponizing a single newly disclosed WinRAR vulnerability.

Third-order effects

  • If the pattern holds, crimeware keeps industrializing around reusable delivery platforms: a single disclosed or leaked vulnerability gets folded into kits within days, as EternalBlue's post-leak life demonstrated, shrinking the window between patch release and mass exploitation.
  • The endpoint defense burden shifts from blocking individual malware samples to detecting the infection chain itself — a gap illustrated by the UEFI rootkit Kaspersky found surviving OS reinstalls and drive replacements, which shows how far below the OS commodity kits can eventually push persistence.

The trend: Exploit kits are turning every disclosed or leaked vulnerability into rented, turnkey infection infrastructure at million-device scale, compressing the time from disclosure to global compromise.