SMOKEDHAM

MITRE ATT&CK: S0649 View on attack.mitre.org

Aliases: SMOKEDHAM

First seen
2021-05-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
37 (37 malicious)
Last IoC activity
2026-09-02 00:34:07
Profile updated
2026-07-07 13:15:25

Targeted industries: financial-services government-and-public-sector professional-services technology-and-telecommunications

Context

SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021; it has been used by at least one ransomware-as-a-service affiliate.

Recent IoC activity

37 malicious indicators in Maltiverse are attributed to SMOKEDHAM (S0649). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname criccode.info 2026-09-03 1
hostname bythedrink.com 2026-09-03 1
hostname brooijmansbct.com 2026-09-03 1
hostname cavtat.biz 2026-09-03 1
hostname mstore.framfarmers.co.uk 2026-09-03 1
hostname automovileshubert.com 2026-09-03 1
hostname ltqcgdkrlhuc1zr6plf4z7qev4y2-1f29a27d56871a58180ed7b698887003.eu5.myvolumio.org 2026-09-03 1
hostname new-porn-zwwxr.blogspot.am 2026-09-03 1
hostname www.devopstechnologies.site 2026-09-03 1
hostname dash-server2.servertech02.workers.dev 2026-09-02 1
hostname server-cd2.bipewi2747.workers.dev 2026-09-02 1
hostname crimson-unit-2561.kopis56799.workers.dev 2026-09-02 1
hostname soft-base-01.ginigiy117.workers.dev 2026-09-02 1
hostname ssl.bapiyat727.workers.dev 2026-09-02 1
hostname app.pofelal314.workers.dev 2026-09-01 1
hostname saddleaxbt.site 2026-08-21 1
hostname www.retirement-communities988.online 2026-07-19 1
hostname soft-dns.sejilod7488888.workers.dev 2026-07-02 1
hostname www.cdn-web-app-10.tech 2026-06-16 1
hostname rufus-dyer.com 2026-06-12 1

Detection coverage

  • 515 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • Hidden Users (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Local Account (attack-pattern)
  • Modify Registry (attack-pattern)
  • Additional Local or Domain Groups (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Service (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Malicious Link (attack-pattern)
  • Web Protocols (attack-pattern)
  • Keylogging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Screen Capture (attack-pattern)
  • PowerShell (attack-pattern)
  • Local Account (attack-pattern)
  • Domain Fronting (attack-pattern)

Reports & references

  • cloud.google.com — Darkside Affiliate Supply Chain Software Compromise (report)
  • cloud.google.com — Burrowing Your Way Into Vpns (report)
  • Mandiant — Shining A Light On Darkside Ransomware Operations (report)
  • Mandiant — Burrowing Your Way Into Vpns (report)
  • Mandiant — Darkside Affiliate Supply Chain Software Compromise (report)
  • Mandiant — Darkside Affiliate Supply Chain Software Compromise (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Smokedham (report)
  • MITRE ATT&CK — S0649 (report)

External references