Smoke Loader
MITRE ATT&CK: S0226 View on attack.mitre.org
Aliases: Dofoil, Sharik, Smoke, Smoke Loader
- First seen
- 2011-01-01 00:00:00
- Malware type
- loader, botnet, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4744 (4397 malicious)
- Last IoC activity
- 2026-09-02 02:45:06
- Profile updated
- 2026-07-07 15:43:34
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications government-and-public-sector
Context
Smoke Loader is a malicious bot application that can be used to load other malware. Smoke Loader has been seen in the wild since at least 2011 and has included a number of different payloads. It is notorious for its use of deception and self-protection. It also comes with several plug-ins.
Recent IoC activity
4,400 malicious indicators in Maltiverse are attributed to Smoke Loader (S0226). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | spasopro.at | 2026-09-03 | 3 |
| hostname | facilitycoursedw.shop | 2026-09-03 | 1 |
| hostname | doughtdrillyksow.shop | 2026-09-03 | 1 |
| hostname | disappointcredisotw.shop | 2026-09-03 | 1 |
| hostname | omfghellobrosjda38.org | 2026-09-03 | 1 |
| hostname | msktk.ru | 2026-09-03 | 2 |
| hostname | soetegem.com | 2026-09-03 | 1 |
| hostname | olihonols.in.net | 2026-09-03 | 1 |
| hostname | gromograd.ru | 2026-09-03 | 1 |
| file sample | 859b9aa8b53f4ac30ffdc0bdb6865543f728eab41141f8ee356b97815bf05907 | 2026-09-02 | 3 |
| URL | http://spasopro.at/index.php | 2026-09-02 | 2 |
| URL | https://spasopro.at/index.php | 2026-09-02 | 2 |
| file sample | 8518533444f9d26fabdd17053c4e69df268c6f3d3ef8be30fd2ab649641b6343 | 2026-09-02 | 2 |
| file sample | fbf05b8c17ae821b9d1df84962a186d0.exe | 2026-09-02 | 1 |
| hostname | blogmstat255.xyz | 2026-09-02 | 1 |
| hostname | wa5zu7sekai8xeih.com | 2026-09-02 | 1 |
| hostname | seattle-fishing-club.com | 2026-09-02 | 1 |
| hostname | hoh0aeghwugh2gie.com | 2026-09-02 | 1 |
| hostname | blogstat355.xyz | 2026-09-02 | 1 |
| hostname | anam0rph.su | 2026-09-02 | 3 |
Detection coverage
- 282 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Credentials In Files (attack-pattern)
- Local Email Collection (attack-pattern)
- Visual Basic (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Web Protocols (attack-pattern)
- System Checks (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Process Hollowing (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Process Injection (attack-pattern)
- Scheduled Task (attack-pattern)
- File and Directory Discovery (attack-pattern)
Used by threat actors
- TA577 (threat-actor)
Exploited vulnerabilities
- CVE-2023-38831 (vulnerability)
- CVE-2025-0411 (vulnerability)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Report2021Gtr (report)
- CISA — Aa22 110A (report)
- malwarebytes.com — Malvertising Campaigns Come Back In Full Swing (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- intel471.com — Privateloader Malware (report)
- deepinstinct.com — Deep Dive Packing Software Cryptone (report)
- Cisco Talos — 2020 Year In Malware (report)
- blackberry.com — Report Bb 2021 Threat Report (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
- marcoramilli.com — C2 Traffic Patterns Personal Notes (report)
- proofpoint.com — 2019 Return Retefe (report)
- intrinsec.com — Tlp Clear From Espionage To Psyops Tracking Operations And Infrastructure Of Uacs In 2025 En 1 (report)
- ptsecurity.com — Antisandbox Techniques (report)
- acronis.com — 8Base Ransomware Stays Unseen For A Year (report)
- logpoint.com — Defending Against 8Base (report)
- blogs.vmware.com — 8Base Ransomware A Heavy Hitting Player (report)
- blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
- blog.cluster25.duskrise.com — Cve 2023 38831 Russian Attack (report)
- team-cymru.com — Seychelles Seychelles On The C 2 Shore (report)
- medium.com — Gcleaner Garbage Provider Since 2019 2708E7C87A8A (report)
- blogs.blackberry.com — Smokeloader Malware Used To Augment Amadey Infostealer (report)