MalSmoke is a cybercriminal threat actor linked (per reporting in the provided content) to a Zloader banking-malware campaign first observed in early November 2021. The campaign uses the legitimate RMM tool Atera for initial access (via an MSI masquerading as a Java installer and associating the agent to an attacker-controlled account), then executes multiple batch scripts to weaken defenses (e.g., modifying Windows Defender preferences, adding exclusions, and disabling tools such as cmd.exe and Task Manager) and stage additional components from teamworks455[.]com. The intrusion chain abuses Microsoft Authenticode verification weakness by appending script content into the signature section of a Microsoft-signed DLL (AppResolver.dll renamed to appContast.dll) while retaining a ‘valid’ signature, then executing the appended script via mshta.exe. Zloader is launched via regsvr32.exe, injects into msiexec.exe, and communicates with C2 infrastructure including lkjhgfgsdshja[.]com and /gate.php endpoints. Persistence is achieved via Startup-folder scripting (auto.bat launching mshta.exe with reboot.dll) and an HKCU Run key that launches regsvr32.exe with a copied Zloader DLL from a newly created %appdata% directory. The report cited 2,170 unique victim IPs as of 2022-01-02, with most victims in the United States and Canada. Attribution to MalSmoke is based on infrastructure and tradecraft overlaps, including Java-plugin masquerading and a registrar linkage between teamworks455[.]com and pornislife[.]online. Separately, the content notes ShadowSyndicate infrastructure being used by multiple threat clusters, including one associated with ‘Malsmoke,’ but provides no additional high-confidence operational details about MalSmoke from that linkage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat cluster leveraging shared ShadowSyndicate-linked infrastructure for malicious operations.
Assessed by the report author as the likely operators behind the described Zloader campaign, based on infrastructure overlap and tradecraft (Java-themed lures/masquerading).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.