SMOKEDHAM is a Windows PowerShell/.NET backdoor and remote access trojan used to maintain interactive access to compromised environments. It periodically contacts command-and-control infrastructure to receive and execute PowerShell or arbitrary .NET commands, supports screenshot capture, keylogging, user and system owner discovery through commands such as whoami, and exfiltrates collected data over its command channel. Its communications have been observed using Base64 encoding and RC4 encryption for command-and-control traffic obfuscation.
SMOKEDHAM has been used to establish persistence through Windows Registry modification, including creation of Run-key autostart entries. Reported registry changes also enabled credential caching for credential access and facilitated lateral movement via Remote Desktop Protocol. The malware has also been delivered through DLL sideloading chains in trojanized software installers, with the backdoor source embedded in the dropper as an encrypted string.
The malware is associated with UNC2465, a ransomware-affiliate cluster linked in reporting to DarkSide and LockBit-related activity. It has been delivered via phishing in some intrusions and via trojanized software distributed through malvertising in others. In observed ransomware operations, SMOKEDHAM functioned as an initial foothold and persistence mechanism preceding credential collection, remote access expansion, lateral movement, data theft, and eventual ransomware deployment. It has been documented in compromises involving enterprise Windows systems and administrator workstations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
le téléchargement et à l'exécution d'un installeur RVTools.exe trojanisé, délivrant un RAT appelé SMOKEDHAM. SMOKEDHAM est une backdoor Powershell .NET qui contacte périodiquement son serveur de commande et de contrôle pour exécuter des commandes PowerShell.
UNC2465 now uses phishing emails to deliver DarkSide via the Smokedham .NET backdoor. Smokedham also supports the execution of arbitrary .NET commands, keylogging, and screenshot generation.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
SMOKEDHAM est une backdoor Powershell .NET qui contacte périodiquement son serveur de commande et de contrôle pour exécuter des commandes PowerShell
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Operation Wocao enabled Wdigest by changing the HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest registry value from 0 (disabled) to 1 (enabled); Wizard Spider modified WDigest UseLogonCredential to 1 to force credentials to be stored in clear text in memory.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
Operation Wocao enabled Wdigest by changing the HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest registry value from 0 (disabled) to 1 (enabled); Wizard Spider modified WDigest UseLogonCredential to 1 to force credentials to be stored in clear text in memory.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
Smokedham also supports the execution of arbitrary .NET commands, keylogging, and screenshot generation
Operation Wocao enabled Wdigest by changing the HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest registry value from 0 (disabled) to 1 (enabled); Wizard Spider modified WDigest UseLogonCredential to 1 to force credentials to be stored in clear text in memory.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Aquatic Panda modified the victim registry to enable the RestrictedAdmin mode feature, allowing for pass the hash behaviors to function via RDP. SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP). SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
des domaines de workers Cloudflare (*.workers.dev), qui servent en réalité à masquer le véritable serveur de commande et de contrôle derrière eux
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell/.NET backdoor delivered via a trojanized RVTools installer. It periodically contacts C2 infrastructure, including Cloudflare Workers domains, to receive and execute PowerShell commands and was used to establish persistence and remote control.
A stealthy backdoor used by UNC2465 for initial access, persistence, reconnaissance, lateral movement, and enabling extortion/ransomware deployment. It is delivered via trojanized installers (e.g., KeyStore Explorer, Angry IP Scanner), uses DLL side-loading and PowerShell obfuscation, manipulates Windows services (e.g., MSDTC) for persistence/privilege escalation, and communicates with C2 using techniques like domain fronting (e.g., Cloudflare Workers) to obscure traffic origins while executing arbitrary PowerShell commands and exfiltrating recon data.
Backdoor that uses whoami to identify system owners.
Malware that executes PowerShell commands received from C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.