SmokeLoader Malware Resurfaces, Targeting Manufacturing and IT in Taiwan

Share:

Taiwanese entities in manufacturing, healthcare, and information technology sectors have become the target of a new campaign distributing the SmokeLoader malware.

“SmokeLoader is well-known for its versatility and advanced evasion techniques, and its modular design allows it to perform a wide range of attacks,” Fortinet FortiGuard Labs said in a report shared with The Hacker News.

“While SmokeLoader primarily serves as a downloader to deliver other malware, in this case, it carries out the attack itself by downloading plugins from its [command-and-control] server.”

SmokeLoader, a malware downloader first advertised in cybercrime forums in 2011, is chiefly designed to execute secondary payloads. Additionally, it possesses the capability to download more modules that augment its own functionality to steal data, launch distributed denial-of-service (DDoS) attacks, and mine cryptocurrency.

“SmokeLoader detects analysis environments, generates fake network traffic, and obfuscates code to evade detection and hinder analysis,” an extensive analysis of the malware by Zscaler ThreatLabz noted.

“The developers of this malware family have consistently enhanced its capabilities by introducing new features and employing obfuscation techniques to impede analysis efforts.”

SmokeLoader activity suffered a major decline following Operation Endgame, a Europol-led effort that took down infrastructure tied to several malware families such as IcedID, SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot in late May 2024. Some of the prominent actors affiliated with SmokeLoader have since been added to the E.U. Most Wanted List.

As many as 1,000 C2 domains linked to SmokeLoader have been dismantled, and more than 50,000 infections have been remotely cleaned. That having said, the malware continues to be used by threat groups to distribute payloads through new C2 infrastructure.

SmokeLoader Malware

This, per Zscaler, is largely due to numerous cracked versions publicly available on the internet.

The starting point of the latest attack chain discovered by FortiGuard Labs is a phishing email containing a Microsoft Excel attachment that, when launched, exploits years-old security flaws (e.g., CVE-2017-0199 and CVE-2017-11882) to drop a malware loader called Ande Loader, which is then used to deploy SmokeLoader on the compromised host.

SmokeLoader consists of two components: a stager and a main module. While the stager’s purpose is to decrypt, decompress, and inject the main module into an explorer.exe process, the main module is responsible for establishing persistence, communicating with the C2 infrastructure, and processing commands.

The malware supports several plugins that can steal login and FTP credentials, email addresses, cookies, and other information from web browsers, Outlook, Thunderbird, FileZilla, and WinSCP.

“SmokeLoader performs its attack with its plugins instead of downloading a completed file for the final stage,” Fortinet said. “This shows the flexibility of SmokeLoader and emphasizes that analysts need to be careful even when looking at well-known malware like this.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:52 pm, Apr 22, 2025
weather icon 17°C
L: 16° | H: 18°
overcast clouds
Humidity: 45 %
Pressure: 1016 mb
Wind: 10 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 94%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:49 am
Sunset: 8:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 18°°C 0 mm 0% 11 mph 67 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 11°°C 1 mm 100% 13 mph 95 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
9° | 15°°C 0.2 mm 20% 6 mph 86 % 1024 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
8° | 16°°C 0 mm 0% 8 mph 87 % 1024 mb 0 mm/h
Sat Apr 26 10:00 pm
weather icon
9° | 13°°C 0.6 mm 60% 4 mph 96 % 1024 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 17°°C 0 mm 0% 10 mph 45 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
14° | 16°°C 0 mm 0% 11 mph 49 % 1016 mb 0 mm/h
Today 10:00 pm
weather icon
10° | 12°°C 0 mm 0% 7 mph 67 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 7 mph 76 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 8°°C 1 mm 100% 10 mph 95 % 1010 mb 0 mm/h
Tomorrow 7:00 am
weather icon
9° | 9°°C 1 mm 100% 12 mph 94 % 1009 mb 0 mm/h
Tomorrow 10:00 am
weather icon
8° | 8°°C 1 mm 100% 13 mph 93 % 1010 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
8° | 8°°C 0.8 mm 80% 10 mph 91 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€78,972.19
3.09%
Ethereum(ETH)
€1,449.31
2.14%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.87
1.12%
Solana(SOL)
€125.55
3.49%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.149625
6.47%
Shiba Inu(SHIB)
€0.000011
2.96%
Pepe(PEPE)
€0.000007
5.61%
Scroll to Top