Last seven days
- First activity
- Jul 21, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2
- Host form
- 0 IP / 7 hostnames
SmokeLoader, also known as Dofoil and SmokeLdr, is a long-running Windows malware family active since at least 2011 that primarily serves as a loader and backdoor for follow-on payloads.
Profile source: Mallory opens in a new tabSMOKELOADER
SmokeLoader, also known as Dofoil and SmokeLdr, is a long-running Windows malware family active since at least 2011 that primarily serves as a loader and backdoor for follow-on payloads. It has been used in criminal operations to deliver additional malware, especially information stealers, and has been associated with the threat actor commonly tracked as Smoky Spider. It also appears in broader crimeware delivery ecosystems involving groups such as TA577 and ransomware operations including 8Base, where it has been used to stage or load later malware components.
SmokeLoader is characterized by heavy packing, runtime API resolution, code obfuscation, and anti-analysis protections. Reported samples use dynamic import reconstruction, API hashing, hidden or indirect control flow, on-demand code decryption, anti-debugging checks, anti-virtualization logic, and process or module enumeration to frustrate reverse engineering and automated analysis. Some variants also perform locale or keyboard-language checks to avoid infecting systems associated with parts of the CIS region.
A common execution pattern involves creating a legitimate process in a suspended state, unmapping its original image, writing a malicious payload into the remote process, adjusting thread context, and resuming execution. This process hollowing workflow has been observed both in unpacking shellcode and in later-stage execution. SmokeLoader has also been observed injecting into legitimate Windows processes such as explorer.exe, including section-based injection techniques, to conceal execution and support command-and-control activity or delivery of additional malware.
Operationally, SmokeLoader is most notable for enabling downstream compromise rather than acting as the final payload itself. Depending on the build and included modules, it can function as a backdoor with modular capabilities while downloading, unpacking, and launching secondary malware. It has been observed in phishing-driven intrusion chains and in malware distribution ecosystems where other loaders or potentially unwanted software can also install it. Its role in the cybercrime supply chain has made it a recurring target of international disruption efforts under Operation Endgame.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
SmokeLoader is a malware that generally acts as a backdoor and is commonly used as a loader for other malware.
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
The SmokeLoader backdoor with a range of capabilities which depend on the modules included in any given build of the malware... 8base uses SystemBC to encrypt command and control traffic and Smokeloader, which provided initial obfuscation of the ransomware on ingress, unpacking, and loading of the Phobos ransomware.
Originally specializing in the Panda banking malware in Italy, it has since branched out to Poland, Germany, Spain, and Japan, using a variety of other malware including Chthonic, Smoke Loader, Nymaim, ZLoader, and finally URLZone in combination with Ursnif, both banking Trojans.
SMOKEY SPIDER is a cybercrime group that develops Smoke Loader (also known as Smoke Bot), a malicious bot that is used to upload other malware. Smoke Loader has been available since at least 2011, and operates as a malware distribution service for a number of different payloads, including—but not limited to—DanaBot, TrickBot, and Qakbot.
We identified and mapped a live SmokeLoader and Fuery botnet operation run by a single operator ("ingermany") using a custom Flask-based C2 panel disguised as an insurance SaaS application.
A SmokeLoader sample (bac70244...3958, module name wallpapers) shares an identical obfuscation framework with Fuery.
"LockBit Group uses #Smokeloader in their attacks"
Exploited software
MITRE ATT&CK
Reporting
Commodity-Payload Command-and-Control, Distribution and Dead-Drop Resolvers (Delivered Malware) SmokeLoader: rcacademy.at/upload/
SmokeLoader6
SmokeLoader7
Previously, the FBI and Europol targeted loaders like Bumblebee (in 2024), as well as others in the dropper/loader ecosystem like IcedID, Pikabot, and Smokeloader.
Proofpoint and IBM X-Force researchers observed StealC-linked activity delivering malware families, including the following: ... SmokeLoader ...
Amadey has also been propagated via other loaders like Emmenhtal and SmokeLoader. ... A total of 53 unique clusters have been inside the Amadey ecosystem, with the largest botnet cluster distributing payloads like Lumma Stealer, Vidar Stealer, StealC, Rugmi, PureCrypter, Agent Tesla, Rhadmanthys Stealer, RedLine Stealer, SmokeLoader, XWorm, and AsyncRAT.
Amadey is in turn also delivered by other loaders, with SmokeLoader among them.
The disruption is the latest phase of Operation Endgame, which previously disrupted other malware families, such as DanaBot, Bumblebee, Rhadamanthys, VenomRAT, Elysium, and SmokeLoader.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.