Skip to content

SMOKELOADER

SmokeLoader, also known as SmokeLdr, is a long-running modular Windows malware family first observed in 2011.

Profile source: Mallory opens in a new tab

SMOKELOADER

Family profile

SmokeLoader, also known as SmokeLdr, is a long-running modular Windows malware family first observed in 2011. It primarily functions as a loader and downloader for additional payloads, while supporting information theft, reconnaissance, persistence, command-and-control, and backdoor-oriented functions through modular components. It has been used to deploy ransomware, banking trojans, cryptominers, point-of-sale malware, and credential stealers.

SmokeLoader has been distributed through malicious Office and PDF documents delivered in spam and targeted spearphishing campaigns, as well as through malvertising and exploit-kit activity. It commonly conceals execution by injecting or hollowing legitimate Windows processes. Known persistence mechanisms include scheduled tasks, Registry autorun mechanisms, and Startup-folder scripts.

The malware can collect credentials stored by web browsers, including Firefox login data, and conduct host and network reconnaissance. It incorporates anti-debugging, anti-sandbox, anti-virtual-machine, anti-hooking, code-obfuscation, runtime decryption, and encrypted payload and network-traffic handling. Variants have used RC4-encrypted command-and-control responses and modular plugins. SmokeLoader has historically been associated with Russian-speaking cybercriminal actors, and it has also been adopted by ransomware affiliates, including Qilin-associated operations.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Persistence
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
2 IP / 19 hostnames

Leading locations

  • DE6
  • US5
  • PL4
  • RU1

Leading providers

  • Hetzner Online GmbH6
  • Scaleway SAS4
  • Amazon.com, Inc.3
  • Cloudflare, Inc.1
  • Google LLC1

Infrastructure traits

  • Hosting 15
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

13 named in public reporting
APT29

"1359593325": "TrickBot/SmokeLoader/Nobelium/APT29 - Stats uniques -> ips/hostnames: 256 publickeys: 183"

UAC-0006

UAC-0006 is a financially motivated threat actor active since at least 2013. They primarily target Ukrainian organizations ... with phishing emails containing the SmokeLoader malware.

SMOKY SPIDER

SmokeLoader is a malware that generally acts as a backdoor and is commonly used as a loader for other malware.

TA505

Smokeloader is a popular bot and a veteran in its field – being sold on underground cybercriminal markets since 2011, this piece of malware is used mainly for loading other malicious software, usually obtained from a third party.

Water Minyades

Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.

Operation STANDOFF

Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : SmokeLoader (loader/backdoor modulaire)

Snatch

По данным Intel 471, инфраструктура yalishanda была связана с группами Snatch Team (data extortion и ransomware), GandCrab, малварью Smokeloader...

TA577

TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.

8Base

The SmokeLoader backdoor with a range of capabilities which depend on the modules included in any given build of the malware... 8base uses SystemBC to encrypt command and control traffic and Smokeloader, which provided initial obfuscation of the ransomware on ingress, unpacking, and loading of the Phobos ransomware.

TA544

Originally specializing in the Panda banking malware in Italy, it has since branched out to Poland, Germany, Spain, and Japan, using a variety of other malware including Chthonic, Smoke Loader, Nymaim, ZLoader, and finally URLZone in combination with Ursnif, both banking Trojans.

Smokey Spider

SMOKEY SPIDER is a cybercrime group that develops Smoke Loader (also known as Smoke Bot), a malicious bot that is used to upload other malware. Smoke Loader has been available since at least 2011, and operates as a malware distribution service for a number of different payloads, including—but not limited to—DanaBot, TrickBot, and Qakbot.

ingermany

A SmokeLoader sample (bac70244...3958, module name wallpapers) shares an identical obfuscation framework with Fuery.

LockBit

"LockBit Group uses #Smokeloader in their attacks"

Exploited software

Vulnerabilities linked to SMOKELOADER

7 CVEs

MITRE ATT&CK

SMOKELOADER in ATT&CK

103 distinct techniques

Techniques

103 techniques
T1562.001 Disable or Modify Tools T1566.001 Spearphishing Attachment T1027 Obfuscated Files or Information T1083 File and Directory Discovery T1555 Credentials from Password Stores T1497 Virtualization/Sandbox Evasion T1055 Process Injection T1071.001 Web Protocols T1046 Network Service Discovery T1053 Scheduled Task/Job T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1105 Ingress Tool Transfer T1555.003 Credentials from Web Browsers T1053.005 Scheduled Task T1059.005 Visual Basic T1189 Drive-by Compromise T1071 Application Layer Protocol T1055.012 Process Hollowing T1140 Deobfuscate/Decode Files or Information T1583.008 Malvertising T1547 Boot or Logon Autostart Execution T1497.001 System Checks T1204.002 Malicious File T1566 Phishing T1203 Exploitation for Client Execution T1027.002 Software Packing T1059.003 Windows Command Shell T1204 User Execution T1204.001 Malicious Link T1041 Exfiltration Over C2 Channel T1059.001 PowerShell T1036 Masquerading T1566.002 Spearphishing Link T1657 Financial Theft T1571 Non-Standard Port T1498 Network Denial of Service T1480.002 Mutual Exclusion T1543 Create or Modify System Process T1622 Debugger Evasion T1059.007 JavaScript T1562 Impair Defenses T1027.007 Dynamic API Resolution T1112 Modify Registry T1012 Query Registry T1047 Windows Management Instrumentation T1496 Resource Hijacking T1486 Data Encrypted for Impact T1518 Software Discovery T1056.001 Keylogging T1125 Video Capture T1059 Command and Scripting Interpreter T1573 Encrypted Channel T1547.009 Shortcut Modification T1565 Data Manipulation T1574 Hijack Execution Flow T1070 Indicator Removal T1057 Process Discovery T1104 Multi-Stage Channels T1584 Compromise Infrastructure T1620 Reflective Code Loading T1564.003 Hidden Window T1665 Hide Infrastructure T1090.003 Multi-hop Proxy T1568.001 Fast Flux DNS T1583.001 Domains T1583.002 DNS Server T1583.003 Virtual Private Server T1583.004 Server T1102.001 Dead Drop Resolver T1106 Native API T1055.001 Dynamic-link Library Injection T1134 Access Token Manipulation T1129 Shared Modules T1027.016 Junk Code Insertion T1614.001 System Language Discovery T1033 System Owner/User Discovery T1070.004 File Deletion T1608.001 Upload Malware T1539 Steal Web Session Cookie T1005 Data from Local System T1037 Boot or Logon Initialization Scripts T1037.001 Logon Script (Windows) T1036.005 Match Legitimate Resource Name or Location T1070.006 Timestomp T1119 Automated Collection T1553.002 Code Signing T1036.001 Invalid Code Signature T1001 Data Obfuscation T1056 Input Capture T1573.001 Symmetric Cryptography T1562.004 Disable or Modify System Firewall T1568 Dynamic Resolution T1027.009 Embedded Payloads T1027.013 Encrypted/Encoded File T1114.001 Local Email Collection T1190 Exploit Public-Facing Application T1552.001 Credentials In Files T1001.003 Protocol or Service Impersonation T1055.002 Portable Executable Injection T1588.002 Tool T1598 Phishing for Information T1055.004 Asynchronous Procedure Call

Reporting

Research mentioning SMOKELOADER

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 15
Gurucul Threat Research

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Community Portal | Gurucul

Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.

Jul 14
Trojan Killer News

Artlist ClickFix Page Dropped a Native Windows RAT

Jul 14
Infostealers Com Infostealers

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | InfoStealers

Jul 14
Malware News

How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist - Malware Analysis - Malware Analysis, News and Indicators

Jul 14
Gurucul Threat Research

ClickFix: Exploiting Compromised WordPress Sites with a Polygon-Based C2 Infrastructure | Community Portal | Gurucul

Jul 14
Derp Ca

From EtherHiding to a native RAT: ClickFix on new-blog.artlist[.]io | Derp

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.