#Smokeloader
Smokeloader keeps crawling its way back into the limelight. If you want a primer on it, I gave a public talk on it 2 years ago

www.youtube.com/watch?v=O69e...
Smokeloader: The Pandora’s box of tricks, payloads and anti-analysis - BSides Portland 2022
YouTube video by BSides Portland
www.youtube.com
November 16, 2024 at 3:42 AM
🚨 SmokeLoader malware is back, now more advanced and dangerous, with enhanced tools to steal harvast credentials - The malware was spotted targeting industries in #Taiwan 💻🔒

Read: hackread.com/smokeloader-...

#CyberSecurity #SmokeLoader #Malware #Taiwan
SmokeLoader Malware Exploits MS Office Flaws to Steal Browser Data
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
December 2, 2024 at 6:46 PM
SmokeLoader Malware Attacking Windows Users Exploiting XLS And DOC Vulnerabilities
SmokeLoader Malware Attacking Windows Users Exploiting XLS And DOC Vulnerabilities
The notorious SmokeLoader malware has been identified targeting firms in Taiwan, including those in manufacturing, healthcare, information
cybersecuritynews.com
December 3, 2024 at 3:55 PM
Huge cybercrime news here. Authorities say they’ve disrupted six types of botnets/loaders/cybercrime infrastructure: IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot #infosec www.europol.europa.eu/media-press/...
Largest ever operation against botnets hits dropper malware ecosystem | Europol
Between 27 and 29 May 2024 Operation Endgame, coordinated from Europol’s headquarters, targeted droppers including, IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot. The actions focused ...
www.europol.europa.eu
May 30, 2024 at 5:21 AM
🚨 #OperationEndgame - With the operators out of the picture, law enforcement is closing in on Smokeloader botnet’s paying customers across Europe and North America.

Read: hackread.com/smokeloader-...

#CyberSecurity #CyberCrime #Smokeloader #Botnet
Smokeloader Users Identified and Arrested in Operation Endgame
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
April 10, 2025 at 4:01 PM
SmokeLoader Malware Exploits MS Office Flaws to Steal Browser Data

#iab #apt #taiwan #prepositioning

cc: @bugcrowd

https://buff.ly/3ZyUPfC
SmokeLoader Malware Exploits MS Office Flaws to Steal Browser Data
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
buff.ly
December 3, 2024 at 12:27 AM
“Thousands of computers around the world have been infected with the SmokeLoader malware by (Nicholas) Moses and over 65,000 victims have had their personal information and passwords stolen by Moses,” court records stated.
Vermont man who admitted to hacking and stole personal data avoids jail time - VTDigger
“Thousands of computers around the world have been infected with the SmokeLoader malware by (Nicholas) Moses and over 65,000 victims have had their personal information and passwords stolen by Moses,”...
vtdigger.org
October 27, 2025 at 9:32 PM
Hackers Exploiting 7-Zip Zero-Day Vulnerability to Deploy SmokeLoader Malware
Hackers Exploiting 7-Zip Zero-Day Vulnerability to Deploy SmokeLoader Malware 
cybersecuritynews.com
February 4, 2025 at 10:44 AM
SmokeLoader Malware Exploits MS Office Flaws to Steal Browser Data https://hackread.com/smokeloader-malware-ms-office-flaws-browser-data/
SmokeLoader Malware Exploits MS Office Flaws to Steal Browser Data
Follow us on Bluesky, Twitter (X) and Facebook at @Hackread
hackread.com
December 3, 2024 at 12:42 PM
🥷
Grosse op contre l’écosystème #malware par @Europol

✅ arrestations
✅ suspension de serveurs
✅ prise de contrôle de sites liés
Largest ever operation against botnets hits dropper malware ecosystem | Europol
Between 27 and 29 May 2024 Operation Endgame, coordinated from Europol’s headquarters, targeted droppers including, IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot. The actions focused ...
www.europol.europa.eu
May 30, 2024 at 6:37 AM
Detect malware named CoffeeLoader, which uses stealthy detection evasion methods and is spread via SmokeLoader, with Sigma rules from SOC Prime Platform.
socprime.com/blog/coffee-...
#infosec #cybersecurity
CoffeeLoader Detection: A New Sophisticated Malware Family Spread via SmokeLoader - SOC Prime
Detect malware named CoffeeLoader, which uses stealthy detection evasion methods and is spread via SmokeLoader, with Sigma rules from SOC Prime Platform.
socprime.com
March 28, 2025 at 1:16 PM
December 2, 2024 at 7:32 PM
Socks55Systemz malware behind Proxy[.]AM proxy service

-had 250k at its peak
-currently has ~120k infected hosts
-was the proxy module in many other botnets such as TrickBot, SmokeLoader, etc

www.bitsight.com/blog/proxyam...
December 9, 2024 at 7:01 PM
Zscaler has spotted a new malware loader named CoffeeLoader, used in the wild since September of last year. The malware was used together and appears to bear similarities with SmokeLoader.

www.zscaler.com/blogs/securi...
CoffeeLoader: A Brew of Stealthy Techniques | ThreatLabz
CoffeeLoader is a new malware loader that employs stealthy techniques including call stack spoofing, sleep obfuscation, and Windows fibers to evade detection.
www.zscaler.com
March 29, 2025 at 10:13 PM
In follow-up activity for Operation Endgame, law enforcement tracked down Smokeloader botnet's customers and detained at least five individuals.
Police detains Smokeloader malware customers, seizes servers
In follow-up activity for Operation Endgame, law enforcement tracked down Smokeloader botnet's customers and detained at least five individuals.
www.bleepingcomputer.com
April 9, 2025 at 1:34 PM
SmokeLoader malware aimed at multiple Ukrainian industries, using bug in file archiver
SmokeLoader malware aimed at multiple Ukrainian industries, using bug in file archiver
Researchers at Trend Micro say Russian hackers exploited a bug in the file archiver 7-Zip to drop SmokeLoader malware into the networks of Ukrainian companies.
therecord.media
February 5, 2025 at 6:15 PM
-TA558 returns to targeting hotels
-SlopAds click-fraud operation disrupted
-AISURU botnet linked to DDoS records
-SmokeLoader returns with new version
-Reports on MacSync and Pure family strains
-Hive0154's SnakeDisk USB worm
-New Zealand sanctions Ember Bear
-New Phoenix Rowhammer attack
September 17, 2025 at 8:00 AM
We identified a new zero-day vulnerability affecting 7-Zip (CVE-2025-0411) being exploited in-the-wild on September 25th, 2024. Russian groups utilized this vulnerability, deploying SmokeLoader for espionage operations targeting #Ukraine during the Russo-Ukrainian War. #infosec #cybersecurity 🔗👇
February 4, 2025 at 3:35 PM
8Base Group Deploying New Phobos Ransomware Variant via SmokeLoader
8Base Group Deploying New Phobos Ransomware Variant via SmokeLoader
The threat actors behind the 8Base ransomware are utilizing a variant of the Phobos ransomware for their attacks.
thehackernews.com
November 18, 2023 at 12:01 PM