Smoky Spider is a criminal threat group associated in the provided content with the use of SmokeLoader and Sasfis, described respectively as loader and downloader malware. The content attributes SmokeLoader to Smoky Spider and notes that SmokeLoader has also been used as a bot in malicious infrastructure. Reported infection vectors for SmokeLoader commonly include phishing-delivered malicious documents, though it may also be loaded by other PUPs, PUAs, or malware. The malware is described as acting primarily as a backdoor and loader for additional malware. The provided reporting describes SmokeLoader as using packed samples, runtime API resolution, code obfuscation, hidden calls, and RET-based control-flow abuse to hinder static analysis. It also includes anti-analysis, anti-VM, and anti-debugging capabilities. Operationally, SmokeLoader is described as creating suspended processes, introducing its binary into the spawned process, performing process hollowing using functions such as ZwUnmapViewOfSection, VirtualAlloc, and ZwWriteVirtualMemory, and then resuming execution. The content further states that SmokeLoader commonly executes explorer.exe and injects into it to perform command-and-control actions or download additional files. Aliases directly present in the content include: smoky_spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Criminal group attributed with using SmokeLoader and Sasfis in malware delivery operations. In this reference, it is associated with phishing-based initial access, use of SmokeLoader as a backdoor/loader, process hollowing, code injection, anti-analysis, anti-VM, and anti-debugging behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.