SmokeLoader Malware Resurfaces, Targeting Manufacturing and IT in Taiwan

Share:

Taiwanese entities in manufacturing, healthcare, and information technology sectors have become the target of a new campaign distributing the SmokeLoader malware.

“SmokeLoader is well-known for its versatility and advanced evasion techniques, and its modular design allows it to perform a wide range of attacks,” Fortinet FortiGuard Labs said in a report shared with The Hacker News.

“While SmokeLoader primarily serves as a downloader to deliver other malware, in this case, it carries out the attack itself by downloading plugins from its [command-and-control] server.”

SmokeLoader, a malware downloader first advertised in cybercrime forums in 2011, is chiefly designed to execute secondary payloads. Additionally, it possesses the capability to download more modules that augment its own functionality to steal data, launch distributed denial-of-service (DDoS) attacks, and mine cryptocurrency.

“SmokeLoader detects analysis environments, generates fake network traffic, and obfuscates code to evade detection and hinder analysis,” an extensive analysis of the malware by Zscaler ThreatLabz noted.

“The developers of this malware family have consistently enhanced its capabilities by introducing new features and employing obfuscation techniques to impede analysis efforts.”

SmokeLoader activity suffered a major decline following Operation Endgame, a Europol-led effort that took down infrastructure tied to several malware families such as IcedID, SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot in late May 2024. Some of the prominent actors affiliated with SmokeLoader have since been added to the E.U. Most Wanted List.

As many as 1,000 C2 domains linked to SmokeLoader have been dismantled, and more than 50,000 infections have been remotely cleaned. That having said, the malware continues to be used by threat groups to distribute payloads through new C2 infrastructure.

SmokeLoader Malware

This, per Zscaler, is largely due to numerous cracked versions publicly available on the internet.

The starting point of the latest attack chain discovered by FortiGuard Labs is a phishing email containing a Microsoft Excel attachment that, when launched, exploits years-old security flaws (e.g., CVE-2017-0199 and CVE-2017-11882) to drop a malware loader called Ande Loader, which is then used to deploy SmokeLoader on the compromised host.

SmokeLoader consists of two components: a stager and a main module. While the stager’s purpose is to decrypt, decompress, and inject the main module into an explorer.exe process, the main module is responsible for establishing persistence, communicating with the C2 infrastructure, and processing commands.

The malware supports several plugins that can steal login and FTP credentials, email addresses, cookies, and other information from web browsers, Outlook, Thunderbird, FileZilla, and WinSCP.

“SmokeLoader performs its attack with its plugins instead of downloading a completed file for the final stage,” Fortinet said. “This shows the flexibility of SmokeLoader and emphasizes that analysts need to be careful even when looking at well-known malware like this.”

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:44 am, Jan 18, 2025
weather icon 2°C
L: 1° | H: 3°
overcast clouds
Humidity: 89 %
Pressure: 1031 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 7 km
Sunrise: 7:56 am
Sunset: 4:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
1° | 3°°C 0 mm 0% 4 mph 90 % 1031 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
1° | 5°°C 0 mm 0% 7 mph 93 % 1024 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 8°°C 0.26 mm 26% 6 mph 97 % 1019 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 95 % 1019 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
4° | 7°°C 1 mm 100% 4 mph 99 % 1012 mb 0 mm/h
Today 9:00 am
weather icon
2° | 2°°C 0 mm 0% 2 mph 89 % 1031 mb 0 mm/h
Today 12:00 pm
weather icon
3° | 5°°C 0 mm 0% 3 mph 83 % 1031 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 6°°C 0 mm 0% 3 mph 75 % 1028 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 88 % 1026 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 3 mph 90 % 1025 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 89 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 91 % 1022 mb 0 mm/h
Tomorrow 6:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 93 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,326.42
0.93%
Ethereum(ETH)
€3,193.60
-3.42%
XRP(XRP)
€3.04
-4.48%
Tether(USDT)
€0.97
-0.02%
Solana(SOL)
€231.29
10.47%
Dogecoin(DOGE)
€0.387292
-3.87%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000022
-6.11%
Pepe(PEPE)
€0.000019
-4.00%
Peanut the Squirrel(PNUT)
€0.52
-15.32%
Scroll to Top