SmokeLoader-Malware taucht wieder auf und zielt auf Fertigung und IT in Taiwan

Teilen:

Taiwanese entities in manufacturing, healthcare, and information technology sectors have become the target of a new campaign distributing the SmokeLoader malware.

“SmokeLoader is well-known for its versatility and advanced evasion techniques, and its modular design allows it to perform a wide range of attacks,” Fortinet FortiGuard Labs said in a report shared with The Hacker News.

“While SmokeLoader primarily serves as a downloader to deliver other malware, in this case, it carries out the attack itself by downloading plugins from its [command-and-control] server.”

SmokeLoader, a malware downloader first advertised in cybercrime forums in 2011, is chiefly designed to execute secondary payloads. Additionally, it possesses the capability to download more modules that augment its own functionality to steal data, launch distributed denial-of-service (DDoS) attacks, and mine cryptocurrency.

“SmokeLoader detects analysis environments, generates fake network traffic, and obfuscates code to evade detection and hinder analysis,” an extensive analysis of the malware by Zscaler ThreatLabz noted.

“The developers of this malware family have consistently enhanced its capabilities by introducing new features and employing obfuscation techniques to impede analysis efforts.”

SmokeLoader activity suffered a major decline following Operation Endgame, a Europol-led effort that took down infrastructure tied to several malware families such as IcedID, SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot in late May 2024. Some of the prominent actors affiliated with SmokeLoader have since been added to the E.U. Most Wanted List.

As many as 1,000 C2 domains linked to SmokeLoader have been dismantled, and more than 50,000 infections have been remotely cleaned. That having said, the malware continues to be used by threat groups to distribute payloads through new C2 infrastructure.

SmokeLoader Malware

This, per Zscaler, is largely due to numerous cracked versions publicly available on the internet.

The starting point of the latest attack chain discovered by FortiGuard Labs is a phishing email containing a Microsoft Excel attachment that, when launched, exploits years-old security flaws (e.g., CVE-2017-0199 and CVE-2017-11882) to drop a malware loader called Ande Loader, which is then used to deploy SmokeLoader on the compromised host.

SmokeLoader consists of two components: a stager and a main module. While the stager’s purpose is to decrypt, decompress, and inject the main module into an explorer.exe process, the main module is responsible for establishing persistence, communicating with the C2 infrastructure, and processing commands.

The malware supports several plugins that can steal login and FTP credentials, email addresses, cookies, and other information from web browsers, Outlook, Thunderbird, FileZilla, and WinSCP.

“SmokeLoader performs its attack with its plugins instead of downloading a completed file for the final stage,” Fortinet said. “This shows the flexibility of SmokeLoader and emphasizes that analysts need to be careful even when looking at well-known malware like this.”

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:04 am, Juni 16, 2025
Wetter-Symbol 13°C
L: 12° | H: 15°
klarer Himmel
Luftfeuchtigkeit: 88 %
Druck: 1027 mb
Wind: 2 mph WNW
Windböe: 3 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 2%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
12° | 15°°C 0 mm 0% 9 mph 88 % 1028 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 26°°C 0 mm 0% 10 mph 78 % 1027 mb 0 mm/h
Mi. Juni 18 10:00 pm
Wetter-Symbol
15° | 27°°C 0 mm 0% 8 mph 72 % 1027 mb 0 mm/h
Do. Juni 19 10:00 pm
Wetter-Symbol
16° | 26°°C 0 mm 0% 12 mph 80 % 1027 mb 0 mm/h
Fr. Juni 20 10:00 pm
Wetter-Symbol
16° | 31°°C 0 mm 0% 10 mph 76 % 1025 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 15°°C 0 mm 0% 3 mph 88 % 1028 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
16° | 20°°C 0 mm 0% 3 mph 79 % 1028 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 4 mph 57 % 1028 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 5 mph 37 % 1026 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 9 mph 47 % 1026 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 66 % 1027 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 4 mph 78 % 1027 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 4 mph 78 % 1027 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,037.71
0.68%
Ethereum(ETH)
€2,229.81
1.36%
Fesseln(USDT)
€0.87
-0.03%
XRP(XRP)
€1.89
0.87%
Solana(SOL)
€135.83
7.23%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.153188
-0.80%
Shiba Inu(SHIB)
€0.000010
0.16%
Pepe(PEPE)
€0.000010
0.81%
Nach oben scrollen