Netskope Threat Labs

Blacole

ATP Sandbox Adv. HeuristicsAV

Blacole is an exploit kit that was active from 2011 to 2013 and delivered malware through drive by web attacks. It embedded hidden redirects and iframe injections into compromised websites, probed visitors for browser and plugin vulnerabilities, and downloaded payloads onto machines that lacked current patches. The family shares its origins and infrastructure with the broader BlackHole exploit kit ecosystem of that era.

First seen
January 2022
Last seen
October 2026
Alert Name
ByteCode-JAVA.Exploit.Blacole
ByteCode-SWF.Exploit.Blacole
Document-PDF.Exploit.Blacole
Email-MSG.Exploit.Blacole
Exploit.JS.Blacole.AL
Exploit.JS.Blacole.AX
Exploit.JS.Blacole.BQ
Exploit.JS.Blacole.DN
Exploit.JS.Blacole.T
Exploit.JS.Blacole.W