MalSmoke is a cybercriminal threat actor associated with malware delivery operations, including campaigns involving Zloader banking malware. The group has been linked to financially motivated activity focused on credential theft and theft of private user information. In observed operations, MalSmoke used legitimate remote monitoring and management software for initial access, then executed batch-script driven staging to weaken host defenses, disable investigative tooling, establish persistence, and deploy additional payloads. The intrusion chain included abuse of Microsoft-signed DLLs modified with appended script content to evade trust controls, execution via native Windows utilities, and process injection into legitimate processes for payload execution. MalSmoke has been associated with infrastructure and tradecraft overlaps across multiple campaigns, including Java-themed installer masquerading and shared operational infrastructure. Reporting has also placed MalSmoke among threat clusters using infrastructure linked to the broader ShadowSyndicate cybercrime ecosystem, alongside several major ransomware and intrusion groups. High-confidence reporting ties MalSmoke to Zloader distribution rather than to a distinct ransomware brand of its own. Known activity indicates a concentration of victims in North America, especially the United States and Canada. The actor’s observed capabilities include initial access through remote administration tooling, credential theft via banking malware, persistence through startup and autorun mechanisms, defense evasion through security-control weakening and signed-file abuse, post-exploitation scripting, and process injection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat cluster leveraging shared ShadowSyndicate-linked infrastructure for malicious operations.
Assessed by the report author as the likely operators behind the described Zloader campaign, based on infrastructure overlap and tradecraft (Java-themed lures/masquerading).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.