216.73.217.22

Technical Analysis of SmokeLoader Version 2025

· Published 16/09/2025 08:02 · Modified 16/09/2025 09:43

Export JSON

Essential information

Published
16/09/2025 08:02
Modified
16/09/2025 09:43
Tags
2025-09-16 anti-analysis bug fixes dofoil evasion techniques malware loader network protocol persistence smoke smokeloader version 2025
Related entities
24 observables, 14 techniques (mitre), 3 malware, 2 others

Description

, a modular active since 2011, has resurfaced with new versions in 2025 after Operation Endgame suppressed its activity. The latest variants, 2025 alpha and 2025, include and improvements to evade detection. Key changes include a new mutex check in the stager, modified mutex name generation, and updates to the main module. The has been slightly adjusted in , and the scheduled task name for has been updated. These versions fix performance issues and include additional measures. Despite efforts to dismantle it, continues to evolve and is used by multiple threat groups.

External references