Smoke Loader

MITRE ATT&CK: S0226 View on attack.mitre.org

Aliases: Dofoil, Sharik, Smoke, Smoke Loader

First seen
2011-01-01 00:00:00
Malware type
loader, botnet, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
4744 (4397 malicious)
Last IoC activity
2026-09-02 02:45:06
Profile updated
2026-07-07 15:43:34

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications government-and-public-sector

Context

Smoke Loader is a malicious bot application that can be used to load other malware. Smoke Loader has been seen in the wild since at least 2011 and has included a number of different payloads. It is notorious for its use of deception and self-protection. It also comes with several plug-ins.

Recent IoC activity

4,400 malicious indicators in Maltiverse are attributed to Smoke Loader (S0226). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname spasopro.at 2026-09-03 3
hostname facilitycoursedw.shop 2026-09-03 1
hostname doughtdrillyksow.shop 2026-09-03 1
hostname disappointcredisotw.shop 2026-09-03 1
hostname omfghellobrosjda38.org 2026-09-03 1
hostname msktk.ru 2026-09-03 2
hostname soetegem.com 2026-09-03 1
hostname olihonols.in.net 2026-09-03 1
hostname gromograd.ru 2026-09-03 1
file sample 859b9aa8b53f4ac30ffdc0bdb6865543f728eab41141f8ee356b97815bf05907 2026-09-02 3
URL http://spasopro.at/index.php 2026-09-02 2
URL https://spasopro.at/index.php 2026-09-02 2
file sample 8518533444f9d26fabdd17053c4e69df268c6f3d3ef8be30fd2ab649641b6343 2026-09-02 2
file sample fbf05b8c17ae821b9d1df84962a186d0.exe 2026-09-02 1
hostname blogmstat255.xyz 2026-09-02 1
hostname wa5zu7sekai8xeih.com 2026-09-02 1
hostname seattle-fishing-club.com 2026-09-02 1
hostname hoh0aeghwugh2gie.com 2026-09-02 1
hostname blogstat355.xyz 2026-09-02 1
hostname anam0rph.su 2026-09-02 3

Detection coverage

  • 282 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Visual Basic (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Checks (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Process Injection (attack-pattern)
  • Scheduled Task (attack-pattern)
  • File and Directory Discovery (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2023-38831 (vulnerability)
  • CVE-2025-0411 (vulnerability)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — Report2021Gtr (report)
  • CISA — Aa22 110A (report)
  • malwarebytes.com — Malvertising Campaigns Come Back In Full Swing (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • intel471.com — Privateloader Malware (report)
  • deepinstinct.com — Deep Dive Packing Software Cryptone (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • blackberry.com — Report Bb 2021 Threat Report (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
  • proofpoint.com — 2019 Return Retefe (report)
  • intrinsec.com — Tlp Clear From Espionage To Psyops Tracking Operations And Infrastructure Of Uacs In 2025 En 1 (report)
  • ptsecurity.com — Antisandbox Techniques (report)
  • acronis.com — 8Base Ransomware Stays Unseen For A Year (report)
  • logpoint.com — Defending Against 8Base (report)
  • blogs.vmware.com — 8Base Ransomware A Heavy Hitting Player (report)
  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • blog.cluster25.duskrise.com — Cve 2023 38831 Russian Attack (report)
  • team-cymru.com — Seychelles Seychelles On The C 2 Shore (report)
  • medium.com — Gcleaner Garbage Provider Since 2019 2708E7C87A8A (report)
  • blogs.blackberry.com — Smokeloader Malware Used To Augment Amadey Infostealer (report)

External references