RIG Exploit Kit 3.0 Used to Infect Over 1.3 Million Computers Worldwide
Version 3.0 of the notorious RIG exploit kit has been released. Researchers at Trustwave have determined that the crimeware has already been used to infect more than 1.3 million devices from all over the world.
Context & Ripple Effects
RIG is one of the crimeware-as-a-service staples of the mid-2010s drive-by ecosystem, and Trustwave's count shows how fast a kit refresh pays off: version 3.0 alone has already touched over 1.3 million machines worldwide. It slots into a supply chain that Cisco had mapped months earlier, when its researchers found 1,800 compromised domains serving a Flash zero day to visitors — the same model of renting web traffic into an infection pipeline that RIG productizes.
What makes the milestone worth watching is who ends up holding the infections: exploit kits are distribution infrastructure, and whatever payload gets swapped in — banking trojans or, increasingly, ransomware — inherits the reach. Later corpus findings show where that leads, from leaked NSA tooling becoming a go-to weapon (EternalBlue) to persistence layers that survive OS reinstalls.
First-order effects
- Over 1.3 million device owners are already compromised by RIG 3.0 traffic, most without any indication beyond browser-level exploitation they never see.
- Security teams tracking Trustwave's reporting now have a new kit fingerprint to hunt for, while the kit's operators gain a fresh revenue line selling access to the infected pool.
Second-order effects
- Payload sellers — ransomware crews above all, given Trustwave's own finding that ransomware attacks quadrupled year-over-year by 2019 — get a cheaper on-ramp than running their own phishing operations.
- Competing kit authors are pushed into an update arms race, since each browser and plugin patch devalues the previous version's exploit set — the dynamic behind McAfee later counting 100+ unique exploits weaponizing a single newly disclosed WinRAR vulnerability.
Third-order effects
- If the pattern holds, crimeware keeps industrializing around reusable delivery platforms: a single disclosed or leaked vulnerability gets folded into kits within days, as EternalBlue's post-leak life demonstrated, shrinking the window between patch release and mass exploitation.
- The endpoint defense burden shifts from blocking individual malware samples to detecting the infection chain itself — a gap illustrated by the UEFI rootkit Kaspersky found surviving OS reinstalls and drive replacements, which shows how far below the OS commodity kits can eventually push persistence.
The trend: Exploit kits are turning every disclosed or leaked vulnerability into rented, turnkey infection infrastructure at million-device scale, compressing the time from disclosure to global compromise.