216.73.217.22

Analysis: SmokeLoader malware distribution

· Published 31/03/2025 19:05 · Modified 01/04/2025 10:27

Export JSON

Essential information

Published
31/03/2025 19:05
Modified
01/04/2025 10:27
Tags
2025-03-31 banking cryptbot emmenhtal infostealers lolbas lumma mshta obfuscation powershell smokeloader
Related entities
6 techniques (mitre), 4 malware, 2 others

Description

A malicious campaign targeting First Ukrainian International Bank has been observed using the loader to distribute malware. The infection chain begins with a deceptive email containing a 7z archive, which extracts to reveal a bait PDF and a shortcut file. The shortcut downloads additional files, leading to the execution of and to retrieve the loader. This loader, disguised as a modified Windows utility, deploys while maintaining a stealthy execution flow. , a modular malware, can download additional payloads, steal credentials, and execute remote commands. The campaign demonstrates the evolving tactics of financially motivated threat actors, leveraging techniques and commercial protection tools for .

External references