Smoke Loader

Description

The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.

SmokeLoader, in addition to being used to download standalone coinminers, is available on underground markets with a built-in coinminer module for an additional fee.

Names

Name
Smoke Loader
SmokeLoader
Smoke
Dofoil
Sharik

Category

Malware

Type

  • Botnet
  • Downloader
  • Miner

Information

Mitre Attack

Malpedia

Alienvault Otx

Other Information

Uuid

c0fb51f1-5f2e-4efc-a59f-70ca9a5f0744

Last Card Change

2025-04-21