SmokeLoader, also known as Dofoil and Smoke Loader, is a modular Windows malware loader sold on underground markets since approximately 2011. Its primary function is to download and execute additional malicious payloads, including ransomware, banking trojans, information stealers, cryptominers, and point-of-sale malware. Its plugin architecture also supports information theft, browser credential harvesting, system and network reconnaissance, and backdoor functionality. Observed payloads include RedLine Stealer and the Laplas clipper, and SmokeLoader has appeared in distribution chains involving Vidar and STOP/Djvu ransomware.
SmokeLoader conceals execution through injection into legitimate Windows processes, including Internet Explorer and Windows Explorer. Its defense-evasion mechanisms include code obfuscation, encrypted strings and payloads, anti-debugging checks, and detection of virtual machines and sandbox environments. Variants inspect hardware-related registry values for virtualization artifacts. Command-and-control communication uses HTTP, and encrypted server responses can deliver additional plugins. SmokeLoader supports persistence and has been observed launching scheduled tasks.
Distribution mechanisms include malicious Word or PDF documents delivered through spam and spearphishing, as well as malvertising campaigns. Attackers have also distributed SmokeLoader by exploiting CVE-2025-0411, a 7-Zip Mark-of-the-Web propagation vulnerability affecting nested archives, in attacks against Ukrainian government and private-sector organizations. SmokeLoader is used by multiple criminal operators, including TA505 and Qilin ransomware affiliates, and has affected organizations across countries and industries. Its infrastructure was among the targets of Operation Endgame in May 2024.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
7-Zip 24.09 이전 버전에서 이중 압축된 파일의 Mark of the Web (MoTW) 플래그가 제대로 전파되지 않는 취약점(CVE-2025-0411)이 발견되었다.
Opportunistic threat actors have attempted to capitalize on the confusion surrounding these vulnerabilities by inserting malware into fake non-vendor patches.
Opportunistic threat actors have attempted to capitalize on the confusion surrounding these vulnerabilities by inserting malware into fake non-vendor patches.
Opportunistic threat actors have attempted to capitalize on the confusion surrounding these vulnerabilities by inserting malware into fake non-vendor patches.
This file is designed to take advantage of the second of the two vulnerabilities mention, CVE-2017-11882, a stack overflow vulnerability in the Microsoft Equation Editor that enables remote code execution on a vulnerable system. ... Conclusion While CVE-2017-0199 and CVE-2017-11882 were discovered in 2017, they are still being actively exploited in this and other malware campaigns. | In this blog, we will examine a recent instance of SmokeLoader, a malware variant that exploits both of these CVEs in its deployment chain. SmokeLoader (also known as Dofoil) has been available on the market in one form or another since 2011. Its primary purpose is to support the distribution of other malware families, such as Trickbot.
This stage uses the first of the two exploits involved in this attack, CVE-2017-0199. It also includes an embedded link that will attempt to download the file “receipt.doc” ... Conclusion While CVE-2017-0199 and CVE-2017-11882 were discovered in 2017, they are still being actively exploited in this and other malware campaigns. | In this blog, we will examine a recent instance of SmokeLoader, a malware variant that exploits both of these CVEs in its deployment chain. SmokeLoader (also known as Dofoil) has been available on the market in one form or another since 2011. Its primary purpose is to support the distribution of other malware families, such as Trickbot.
Spelevo Exploit Kitは2つの脆弱性(CVE-2018-8174とCVE-2018-15982)を悪用することが報告されていますが、PseudoGateによる攻撃ではCVE-2018-15982のみが観測されています。CVE-2018-15982はAdobe Flash PlayerのRCEの脆弱性です。
14 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recently sought someone to build an encryptor for their “Smoke Loader” malware.
The Smoke Loader banking trojan, used by TA505, checks registry key values in System\CurrentControlSet\Enum\IDE and System\CurrentControlSet\Enum\SCSI
"1359593325": "TrickBot/SmokeLoader/Nobelium/APT29 - Stats uniques -> ips/hostnames: 256 publickeys: 183"
UAC-0006 is a financially motivated threat actor active since at least 2013. They primarily target Ukrainian organizations ... with phishing emails containing the SmokeLoader malware.
SmokeLoader is a malware that generally acts as a backdoor and is commonly used as a loader for other malware.
Batloader has been observed to drop several malware payloads, such as Ursnif, Vidar, Bumbleloader, RedLine Stealer, ZLoader, Cobalt Strike, and SmokeLoader.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE Attack Techniques: Sr. No. Tactics Technique 2 Execution(TA0002) Shellcode Scheduled Task
MITRE Attack Techniques: Sr. No. Tactics Technique 2 Execution(TA0002) Shellcode Scheduled Task
MITRE Attack Techniques: Sr. No. Tactics Technique 2 Execution(TA0002) Shellcode Scheduled Task
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Multiple advance anti-debugging and analysis detection techniques. Anti-Sandbox, Anti-VM, and Anti-Hooking techniques. Code obfuscation techniques to thwart analysis. Decrypts code prior to execution and encrypts again after execution.
Once the victim downloads and opens the malicious document, the malware drops to the system and in the next stage injects malicious code into a compromised system process like explorer.exe and starts its malicious activity in disguise as a legitimate process.
MITRE Attack Techniques: Sr. No. Tactics Technique 6 Credential Access (TA0006) Credentials from Web Browsers & Files
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Stealing confidential information. System and Network Reconnaissance.
Stealing confidential information. System and Network Reconnaissance.
MITRE Attack Techniques: Sr. No. Tactics Technique 7 Discovery(TA0007) Files and Directories Discovery
1,601 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercially supplied malware downloader used to install secondary payloads. The article dates criminal sales to approximately 2011 and describes its disruption during Operation Endgame in 2024.
A malware loader reportedly adopted by Qilin affiliates in 2024 and 2025.
Modular malware used to download and execute additional payloads.
SmokeLoader is referenced as malware involved in earlier 7-Zip/Mark-of-the-Web bypass attack reporting; no further functional detail is provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.