Skip to content

SmartLoader

SmartLoader is a Windows malware loader used in large-scale fake GitHub repository campaigns, including the FakeGit and AgentBaiting operations.

Profile source: Mallory opens in a new tab

SmartLoader

Family profile

SmartLoader is a Windows malware loader used in large-scale fake GitHub repository campaigns, including the FakeGit and AgentBaiting operations. It is commonly delivered through trojanized ZIP archives embedded in cloned or impersonated developer projects, especially AI tools, developer utilities, game cheats, and Model Context Protocol or AI skill lures. Typical delivery packages contain a batch launcher, a renamed LuaJIT interpreter or runtime components, and a heavily obfuscated Lua payload disguised as a text or log file. Execution of the launcher starts the Lua-based stager, allowing the malware to blend into seemingly legitimate project files and evade simplistic file-based inspection.

SmartLoader is characterized by its LuaJIT-based staging architecture, extensive obfuscation, and dynamic command-and-control discovery. Multiple analyses associate its first-stage scripts with Prometheus-style Lua obfuscation, while later stages have shown indicators consistent with MoonSec. The malware uses anti-debugging and anti-tamper logic, suppresses visible console windows, fingerprints the host, performs internet and geolocation checks, and captures screenshots. It can exfiltrate host metadata and screenshots to its operators and uses the Polygon blockchain as a dead-drop resolver for command-and-control information, enabling operators to rotate infrastructure without rebuilding the malware.

Persistence is commonly established through Windows scheduled tasks, including redundant recovery paths that can relaunch a cached local stage or re-download encrypted stages from GitHub. SmartLoader also retrieves additional encrypted payloads from attacker-controlled GitHub repositories and contains functionality consistent with in-memory loading of follow-on payloads. In observed campaigns, SmartLoader has been used to deliver information stealers including StealC, Lumma Stealer, Vidar Stealer, and a previously reported NodeJS-based malware-as-a-service infostealer. Follow-on payloads have targeted browser credentials, cookies, cryptocurrency wallet data, email-related data, tokens, and other sensitive information.

The malware has been heavily associated with abuse of trust in open-source ecosystems and developer workflows. Campaigns using SmartLoader have impersonated legitimate repositories, copied documentation and project metadata, and leveraged public AI capability catalogs and AI assistants to increase discovery of malicious projects. Victims have been concentrated in North America, Asia, and Southern Europe, with notable targeting of financial services, banking, and technology organizations, although the lures also target individual developers and consumers.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 31, 2026
Last activity
Aug 31, 2026
Feed role
C2 / Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • NL1

Leading providers

  • Local NCC Ltd.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
TroysDen’s

Together, the four files make up SmartLoader, a malware loader Netskope has previously seen distributed through GitHub repositories.

Water Kurita

There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware... Upon activation, the attack launches a LuaJIT-based loader that launches an obfuscated Lua script to install SmartLoader.

FakeGit

A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects and public capability catalogs.

MITRE ATT&CK

SmartLoader in ATT&CK

43 distinct techniques

Reporting

Research mentioning SmartLoader

Jul 24
Cyber Security News

FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users

A malvertising campaign dubbed FakeAgent abused searches for the Claude Desktop app to deliver the SectopRAT information-stealing trojan to Windows users at at least 29 organizations. Victims who clicked sponsored Bing results were sent to a spoofed public artifact hosted on Anthropic's claude.ai domain instead of the legitimate download page, then redirected to attacker-controlled infrastructure that served a fake ClaudeDesktop.exe installer. Huntress said the activity ran from July 21 to 22 and should be treated as a full remote-access and credential-theft compromise, not a nuisance adware incident. The malware chain used DLL sideloading through a tampered libcef.dll, signed-binary proxy execution, VMProtect packing, GPU-based anti-analysis, and DirectX shader-based payload decryption to evade detection. Researchers said SectopRAT established persistence with sslconf.exe, tempdir.dll, and appcfg.dat under AppData, and retrieved command data via blockchain infrastructure tied to contract 0xc1907d7be91f95903ad66d775c397302e7dd9228; Huntress also identified 2.24.131[.]246 as a live command-and-control address. The RAT is capable of stealing browser credentials, cookies, autofill and payment data, Chromium keys, FTP credentials, Discord and messaging data, files, and passwords, and the infrastructure was linked to earlier malicious activity dating to May 2025, including domains associated with campaigns tied to StealC infrastructure seized during Operation Endgame.

Jul 23
Security Affairs

Chaos ransomware deploys browser-based msaRAT to evade network detection - Security Affairs

Cisco Talos reported that the Chaos ransomware group is using a new Rust-based remote access trojan, msaRAT, to conceal command-and-control traffic inside legitimate browser activity. Instead of making direct outbound connections, the malware launches a headless Google Chrome or Microsoft Edge instance with the Chrome DevTools Protocol enabled, injects JavaScript, and uses the browser to establish a WebRTC DataChannel for encrypted communications. Talos said the malware combines WebRTC DTLS with its own ChaCha-Poly1305 encryption using an ECDH-derived shared key, giving operators covert tunneling, browser-assisted remote code execution, and asynchronous multi-threaded control. The reported intrusion chain begins with email or voice phishing, followed by the use of remote management software for persistence and delivery of an MSI installer disguised as a Windows update. That installer, identified as update_ms.msi, is downloaded over plain HTTP on port 443, extracts lib.dll, and loads it directly into memory before starting the browser in remote debugging mode. For signaling, the browser communicates with a Cloudflare Workers endpoint, while Twilio TURN infrastructure relays WebRTC traffic, a design that obscures attacker-controlled systems and makes network-based detection and attribution more difficult.

Jul 23
Cyber Security News

Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel

Jul 23
The Hacker News

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Jul 23
Trojan Killer News

Fake Claude Desktop Ads Dropped SectopRAT | Trojan Killer

Jul 23
Malware News

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel - Malware News - Malware Analysis, News and Indicators

Jul 23
Talosintelligence Other

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Jul 23
Bleeping Computer

Fake Claude app promoted by Bing ads pushes SectopRAT malware

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.