#Smokeloader
SmokeLoader hollows out explorer.exe, then fakes 404s from Microsoft and Bing to hide its C2 traffic. https://intel.threadlinqs.com/threat/TL-2026-2482 #ThreatIntel #Smoke #SmokeLoader #SmokySpider
September 13, 2026 at 11:33 PM
SmokeLoader はそれ単体で情報の窃取機能があり、かつもちろんバックドアを仕掛けるものになります。

で、そのバックドアを経由して別のランサムウェアなどを送り込んだり、勝手に操作したり、情報を好きなタイミングで抜き取ったり、画面の情報や操作をリアルタイムで追跡したり、場所を確認したり、同じ LAN 内の機器に感染を広げたり、ボットネットに組み込んだりできるわけで...

...ところで、最近の Wi-Fi 7 対応ルーターってかなり高性能だよね。
でも、ルーター用のウイルス除去ソフトとか、強制リセット手段って...あんまりないよね。
July 1, 2026 at 10:17 AM
pixivFANBOX において、運営を名乗り「n 時間以内にリンクにアクセスし認証をしなければ投稿が停止される」などと言った偽の警告文をコメントに投稿するスパムが流行っていますが、入力する以前に

⚠ 絶 対 に ア ク セ ス し な い で !

何らかの脅威アクターによる SmokeLoader 系のマルウェアを用いた攻撃が確認されています。このマルウェアはデバイス上のあらゆる情報の漏洩や、遠隔操作を可能にするバックドアの設置を可能にし、ランサムウェアとの連携によるデータ損失や身代金等の要求などの影響があります。
大変危険なので、絶対にアクセスは避けてください。
July 1, 2026 at 6:32 AM
ErrTraffic is a MaaS ClickFix framework using compromised WordPress sites and fake AI pages to spread payloads via EtherHiding and blockchain-based C2, linked to Vidar, Stealc, DanaBot, and more. #ErrTraffic #ClickFix #EtherHiding
Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework
Sekoia TDR analyzed ErrTraffic, a MaaS ClickFix framework that abuses compromised WordPress sites and fake AI-themed websites to distribute payloads through EtherHiding and blockchain-based C2 resolution. The report separates “Analytics” and “Beer” clusters, links them to different operators and campaigns, and highlights payloads such as Vidar, Stealc, Remus, Salat, DanaBot, HijackLoader, and SmokeLoader. #ErrTraffic #ClickFix #EtherHiding #WordPress #Vidar #DanaBot #HijackLoader #SmokeLoader
www.hendryadrian.com
June 16, 2026 at 5:45 PM
Redline stealer is more sophisticated than I knew. The tech involved with unraveling to its packed .NET code was entertainingly formiddable, last time I had this much fun reversing malware was when I was taking apart SmokeLoader.
May 19, 2026 at 5:10 AM
Ok, we get it, LLMs can reverse malware.
But, I’d love to see a fully analysis (similar to what Check Point has done with XLoader) of SmokeLoader, GuLoader, POORTRY, FlawedGrace or Nymain. Not just toy malware

🔁 RT @s4tan | reposted by @hasherezade
https://x.com/s4tan/status/2028470601753432074
March 2, 2026 at 3:23 PM
1つのコードですべてをロック:LockBit 5.0はWindows、Linux、ESXiへの攻撃を統合します

One Code to Lock Them All: LockBit 5.0 Unifies Attacks on Windows, Linux, and ESXi #DailyCyberSecurity (Feb 16)

securityonline.info/one-code-to-...
One Code to Lock Them All: LockBit 5.0 Unifies Attacks on Windows, Linux, and ESXi
LockBit 5.0 launches with a unified codebase targeting Windows, Linux, and ESXi. Acronis reveals identical encryption and ties to SmokeLoader.
securityonline.info
February 17, 2026 at 10:30 PM
高度なフィッシングキャンペーンがウクライナ最大の銀行を標的に

金銭目的の脅威グループUAC-0006が主導する新たなフィッシングキャンペーンが発見され、ウクライナ最大の国有金融機関であるPrivatBankの顧客を標的にしていることが判明しました。 CloudSEKのサイバーセキュリティアナリストは、検知回避のために悪意のあるJavaScript、VBScript、またはLNKファイルを含むパスワード保護されたアーカイブを用いる進行中の攻撃を特定しました。 攻撃手法とペイロード…
高度なフィッシングキャンペーンがウクライナ最大の銀行を標的に
金銭目的の脅威グループUAC-0006が主導する新たなフィッシングキャンペーンが発見され、ウクライナ最大の国有金融機関であるPrivatBankの顧客を標的にしていることが判明しました。 CloudSEKのサイバーセキュリティアナリストは、検知回避のために悪意のあるJavaScript、VBScript、またはLNKファイルを含むパスワード保護されたアーカイブを用いる進行中の攻撃を特定しました。 攻撃手法とペイロード UAC-0006は2024年11月以降、支払いをテーマにしたフィッシング誘導を展開していることが確認されており、以下を悪用しています: 請求書を装った悪意のあるメール添付ファイル PowerShellコマンドを実行するJavaScriptおよびVBScriptファイル コマンド&コントロール(C2)通信のためのSmokeLoader マルウェア これらの手法により、不正アクセス、ペイロードの実行、侵害されたシステムに対する持続的な制御が可能になります。 最新の攻撃は、パスワード保護されたZIPまたはRARファイルを含むフィッシングメールから始まります。開封すると、展開されたJavaScriptまたはVBScriptファイルが一連のプロセスを開始し、正規のWindowsバイナリに悪意のあるコードを注入します。 戦術の進化と帰属 最近のフォレンジック分析によると、UAC-0006は新たな攻撃ベクターとしてLNKファイルを採用しており、ロシアの高度持続的脅威(APT)グループFIN7に以前関連付けられていた戦術を踏襲しています。 これらの変化は、いずれも金融サイバー犯罪で知られるEmpireMonkeyおよびCarbanakとの作戦上の重なりを示唆しています。PowerShell、プロセスインジェクション、非標準のC2通信手法の使用は、同グループの過去のmodus operandi(典型的な手口)と一致します。 フィッシングキャンペーンは、データ侵害など複数のリスクをもたらし、その後、盗まれた認証情報や金融情報が詐欺に利用されたり、ダークウェブで販売されたりする可能性があります。また、銀行や企業アカウントへの不正アクセスを可能にすることで、認証情報の収集(クレデンシャル・ハーベスティング)も促進します。 さらに、フィッシングメールでなりすましに利用されたPrivatBankやその他の組織は、評判の低下を被る可能性があります。金融サービス提供者のなりすましは、サプライチェーン内の下流リスクを増大させます。 サプライチェーンリスクについて詳しく読む:CISA、米国ソフトウェアサプライチェーンの透明性向上を要請 推奨される緩和策 これらの脅威に対抗するため、サイバーセキュリティ専門家は以下を推奨しています: 悪性指標のブロック: UAC-0006に関連するURL、IP、ファイルハッシュを監視し、ブラックリスト化する セキュリティ意識向上トレーニング: 従業員にフィッシングの試みを識別できるよう教育する インシデント対応措置: 被害が発生する前に攻撃を検知・緩和するためのプロトコルを確立する UAC-0006の継続的な進化は、金銭目的のサイバー犯罪グループの高度化が進んでいることを浮き彫りにしています。警戒、能動的な防御戦略、そしてユーザーの意識向上は、これらの脅威を緩和するうえで引き続き重要です。 翻訳元:
blackhatnews.tokyo
February 7, 2026 at 6:36 AM
🚨Exposing #LOCKBIT 5.0 Server: IP & DOMAIN

IP: 205.185.116.233 🇺🇸
#AS53667

Domain: karma0[.]xyz
Reg: 2 November 2025

💡LockBit Group uses #Smokeloader in their attacks
MD5: e818a9afd55693d556a47002a7b7ef31

#Lockbit5 #Ransomware #Security #Intelligence #OSINT #Databreach
December 6, 2025 at 2:17 AM
#Rhadamanthys and #VenomRAT are the latest malware to be disrupted by Operation Endgame.

Since May 2024, the operation has affected IcedID, Bumblebee, SystemBC, Pikabot, SmokeLoader, DanaBot, WarmCookie, Trickbot, and Hijack Loader, among other malware and botnets.
November 13, 2025 at 3:55 PM
“Thousands of computers around the world have been infected with the SmokeLoader malware by (Nicholas) Moses and over 65,000 victims have had their personal information and passwords stolen by Moses,” court records stated.
Vermont man who admitted to hacking and stole personal data avoids jail time - VTDigger
“Thousands of computers around the world have been infected with the SmokeLoader malware by (Nicholas) Moses and over 65,000 victims have had their personal information and passwords stolen by Moses,”...
vtdigger.org
October 27, 2025 at 9:32 PM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 63

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter SmokeLoader Rises From the Ashes  Hive0154, aka Mustang Panda, drops updated Tone…

#hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 63
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter SmokeLoader Rises From the Ashes  Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages  Self-replicating Shai-hulud worm spreads […]
securityaffairs.com
September 22, 2025 at 4:43 PM
-TA558 returns to targeting hotels
-SlopAds click-fraud operation disrupted
-AISURU botnet linked to DDoS records
-SmokeLoader returns with new version
-Reports on MacSync and Pure family strains
-Hive0154's SnakeDisk USB worm
-New Zealand sanctions Ember Bear
-New Phoenix Rowhammer attack
September 17, 2025 at 8:00 AM
SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks
SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks
cybersecuritynews.com
September 16, 2025 at 9:42 AM
SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks SmokeLoader, first seen on criminal forums in 2011, has evolved into a highly modular malware loader des...

#cyberf="/hashtag/Cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Threats #cyber #security #cyber #security #news

Origin | Interest | Match
SmokeLoader Utilizes Optional Plugins To Perform Tasks Such as Stealing Data and DoS Attacks
SmokeLoader, active since 2011, resurged in 2025 with new variants enhancing evasion, plugins, and stealthy delivery of malware.
cybersecuritynews.com
September 16, 2025 at 9:44 AM
SmokeLoader Rises From the Ashes: Deconstructing the Persistent Malware Threat

Introduction: The recent re-emergence of SmokeLoader, a sophisticated malware loader, underscores a critical trend in the cyber threat landscape: the evolution of legacy threats with enhanced anti-analysis and…
SmokeLoader Rises From the Ashes: Deconstructing the Persistent Malware Threat
Introduction: The recent re-emergence of SmokeLoader, a sophisticated malware loader, underscores a critical trend in the cyber threat landscape: the evolution of legacy threats with enhanced anti-analysis and persistence capabilities. This malware's latest variant demonstrates a cunning method of operational resilience by repeatedly reinjecting itself into a core system process, making eradication exceptionally difficult for defenders. Understanding its mechanics is paramount for cybersecurity professionals tasked with defending enterprise networks.
undercodetesting.com
September 16, 2025 at 5:28 AM
Technical Analysis of SmokeLoader Version 2025
Technical Analysis of SmokeLoader Version 2025
www.zscaler.com
September 15, 2025 at 8:39 PM
~Zscaler~
SmokeLoader resurfaces with a new 'v2025' variant, featuring bug fixes and updated evasion techniques following the 'Operation Endgame' takedown.
-
IOCs: (None identified)
-
#Malware #SmokeLoader #ThreatIntel
SmokeLoader Malware Returns with Version 2025
www.zscaler.com
September 15, 2025 at 8:02 PM
ArmouryLoader Bypassing System Security Protections and Inject Malicious Codes ArmouryLoader burst onto the threat landscape in late 2024 after hijacking the export table of ASUS’s Armoury Crate ...

#cyberf="/hashtag/Cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Threats #cyber #security #cyber #security #news

Origin | Interest | Match
ArmouryLoader Bypassing System Security Protections and Inject Malicious Codes
ArmouryLoader hijacks ASUS Armoury Crate, decrypts payloads in GPU memory, and stealthily deploys malware like SmokeLoader without files.
cybersecuritynews.com
July 29, 2025 at 9:14 PM