Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 19 hostnames
SmokeLoader, also known as SmokeLdr, is a long-running modular Windows malware family first observed in 2011.
Profile source: Mallory opens in a new tabSMOKELOADER
SmokeLoader, also known as SmokeLdr, is a long-running modular Windows malware family first observed in 2011. It primarily functions as a loader and downloader for additional payloads, while supporting information theft, reconnaissance, persistence, command-and-control, and backdoor-oriented functions through modular components. It has been used to deploy ransomware, banking trojans, cryptominers, point-of-sale malware, and credential stealers.
SmokeLoader has been distributed through malicious Office and PDF documents delivered in spam and targeted spearphishing campaigns, as well as through malvertising and exploit-kit activity. It commonly conceals execution by injecting or hollowing legitimate Windows processes. Known persistence mechanisms include scheduled tasks, Registry autorun mechanisms, and Startup-folder scripts.
The malware can collect credentials stored by web browsers, including Firefox login data, and conduct host and network reconnaissance. It incorporates anti-debugging, anti-sandbox, anti-virtual-machine, anti-hooking, code-obfuscation, runtime decryption, and encrypted payload and network-traffic handling. Variants have used RC4-encrypted command-and-control responses and modular plugins. SmokeLoader has historically been associated with Russian-speaking cybercriminal actors, and it has also been adopted by ransomware affiliates, including Qilin-associated operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
047e138efd0c8dbb52cc949ad66ffc45f4a64eeecd7d35fc2fa473495785fb1a 5760bf3dfa834dd40a2d43d948d7bb617014f6fd324bd8be6701e91f9176921f 6acc0714d3cbab8c42b03d03044f0c56134ed9a651bd1f7a88d8c8f56c978f6a 8684751f02d87ad7979218ee32929bd7d1dbad5f22dd78016f4d9d9144662ece 94ef48cdfeaf9733cab63ef0b640c506856ed636da5c6760ed6727a005657b19 5d192752f52851d5f724cdbc6d69f560942dae759892ea72f7225ceddef357dc 6ddfc497d6820a9d69bbf6e4b63f2e1011da87479fa89392d983eef3437bb907 92ff907d823740d5bc0263eccb4ddf72ad290f26032d8835b8682a3d75a1f14e 9a203a1f050818238d950b70465e679c6475cf974e7c823d188645ba6aec01ae cd1e5d43202f27d75d48c1d6963ef572eb3321e1ca3d6510c6a999598db09a07 Reported operators
"1359593325": "TrickBot/SmokeLoader/Nobelium/APT29 - Stats uniques -> ips/hostnames: 256 publickeys: 183"
UAC-0006 is a financially motivated threat actor active since at least 2013. They primarily target Ukrainian organizations ... with phishing emails containing the SmokeLoader malware.
SmokeLoader is a malware that generally acts as a backdoor and is commonly used as a loader for other malware.
Smokeloader is a popular bot and a veteran in its field – being sold on underground cybercriminal markets since 2011, this piece of malware is used mainly for loading other malicious software, usually obtained from a third party.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
Il dépose entre 40 et 50 exécutables ... et installe simultanément plusieurs familles de malwares : SmokeLoader (loader/backdoor modulaire)
По данным Intel 471, инфраструктура yalishanda была связана с группами Snatch Team (data extortion и ransomware), GandCrab, малварью Smokeloader...
TA577, are a Russia-based threat group that have been reported to deliver payloads including Qbot, IcedID, SystemBC, SmokeLoader, Ursnif, and Cobalt Strike in ongoing phishing campaigns since 2020.
The SmokeLoader backdoor with a range of capabilities which depend on the modules included in any given build of the malware... 8base uses SystemBC to encrypt command and control traffic and Smokeloader, which provided initial obfuscation of the ransomware on ingress, unpacking, and loading of the Phobos ransomware.
Originally specializing in the Panda banking malware in Italy, it has since branched out to Poland, Germany, Spain, and Japan, using a variety of other malware including Chthonic, Smoke Loader, Nymaim, ZLoader, and finally URLZone in combination with Ursnif, both banking Trojans.
SMOKEY SPIDER is a cybercrime group that develops Smoke Loader (also known as Smoke Bot), a malicious bot that is used to upload other malware. Smoke Loader has been available since at least 2011, and operates as a malware distribution service for a number of different payloads, including—but not limited to—DanaBot, TrickBot, and Qakbot.
A SmokeLoader sample (bac70244...3958, module name wallpapers) shares an identical obfuscation framework with Fuery.
"LockBit Group uses #Smokeloader in their attacks"
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Attackers compromised the Artlist WordPress subdomain new-blog.artlist[.]io and used it to deliver a sophisticated ClickFix malware campaign that presented visitors with a fake CAPTCHA and tricked them into running PowerShell. The injected JavaScript used an EtherHiding technique, querying a Polygon smart contract to dynamically retrieve the next-stage host auth-code-check[.]info, then downloaded a multi-stage infection chain from the attacker-controlled backend. Researchers traced the intrusion to WordPress credentials stolen from an Israeli freelance developer whose machine had been infected by an infostealer after downloading a pirated copy of Adobe Acrobat Pro DC in 2023. The payload chain reportedly used a password-protected archive, a signed StruSoft/FEM-Design updater, and DLL side-loading to decode shellcode and load a final native RAT that supported encrypted and Tor-backed C2, browser credential theft, keylogging, clipboard and screen access, hidden desktop interaction, file transfer, shell and process control, SOCKS proxying, service installation, and in-memory PE delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.