SMOKEDHAM is a Windows PowerShell/.NET backdoor used to establish persistent remote access and support follow-on intrusions. It periodically contacts command-and-control infrastructure, executes operator-supplied PowerShell commands through .NET Runspaces, and returns command output. Its capabilities include keylogging, desktop screenshot capture, host and user discovery, and data exfiltration. It registers infected systems using computer, domain, and username information and protects command-and-control tasking and responses with RC4 encryption and Base64 encoding. Campaigns have used Cloudflare Workers to conceal command-and-control infrastructure.
SMOKEDHAM has been distributed through phishing and malvertising, including trojanized installers impersonating RVTools and Remote Desktop Manager. Delivery chains have used NSIS installers, multistage Python loaders, encrypted embedded C# source, in-memory compilation and execution, and DLL sideloading through legitimate applications. Persistence mechanisms include Registry Run entries, Startup-folder shortcuts, scheduled tasks, and service-based DLL loading. SMOKEDHAM has also created local accounts, added them to administrator groups, and modified Windows settings to enable credential caching and facilitate lateral movement through Remote Desktop Protocol.
SMOKEDHAM is associated with UNC2465, a financially motivated threat actor historically linked to DarkSide ransomware operations. It has also served as an initial foothold in intrusions culminating in Hunters International and Qilin ransomware deployment. In these operations, attackers used the backdoor alongside monitoring software, remote-access tools, and tunneling utilities before data theft and ransomware execution. Observed targets include enterprise Windows workstations and servers, including administrator workstations; subsequent ransomware attacks against VMware ESXi infrastructure involve separate payloads rather than an ESXi version of SMOKEDHAM.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
All three infection chains observed by our analysts revealed the use of the SmokedHam backdoor, delivered through malvertising and masquerading as common utility installers for RVTools or Remote Desktop Manager (RDM).
le téléchargement et à l'exécution d'un installeur RVTools.exe trojanisé, délivrant un RAT appelé SMOKEDHAM. SMOKEDHAM est une backdoor Powershell .NET qui contacte périodiquement son serveur de commande et de contrôle pour exécuter des commandes PowerShell.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Adversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight C#/.NET backdoor apparently derived from ThunderShell. Malicious installers deliver it through obfuscated Python and PowerShell stages, often compiling and executing the implant in memory. It polls HTTP C2 endpoints behind Cloudflare Workers, uses RC4-encrypted JSON tasking, executes arbitrary PowerShell, and returns command output. More capable variants support cached modules and dynamic in-memory assemblies. In the investigated incidents, it enabled surveillance-tool installation, lateral movement, data theft, and subsequent Qilin deployment. Attribution to UNC2465 is assessed with moderate confidence.
PowerShell/.NET backdoor delivered via a trojanized RVTools installer. It periodically contacts C2 infrastructure, including Cloudflare Workers domains, to receive and execute PowerShell commands and was used to establish persistence and remote control.
A stealthy backdoor used by UNC2465 for initial access, persistence, reconnaissance, lateral movement, and enabling extortion/ransomware deployment. It is delivered via trojanized installers (e.g., KeyStore Explorer, Angry IP Scanner), uses DLL side-loading and PowerShell obfuscation, manipulates Windows services (e.g., MSDTC) for persistence/privilege escalation, and communicates with C2 using techniques like domain fronting (e.g., Cloudflare Workers) to obscure traffic origins while executing arbitrary PowerShell commands and exfiltrating recon data.
Backdoor that uses whoami to identify system owners.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.