SmartLoader is a malware distribution threat actor associated with campaigns that deliver information stealers through deceptive software distribution and supply-chain style lures. The actor has been linked to operations that impersonate legitimate developer tooling and package ecosystems in order to compromise developers and harvest sensitive data. In one documented campaign, SmartLoader cloned a legitimate MCP server project related to Oura integrations, built a fabricated ecosystem of seemingly credible developer accounts and forks, and later introduced a trojanized version to public MCP registries to increase adoption by unsuspecting developers. The actor’s tradecraft emphasizes social engineering, trust fabrication, and malware staging through developer-focused channels rather than direct exploitation alone. Reported techniques include creation of fake personas, spoofed open-source credibility signals, and malicious repackaging of legitimate projects. Payload delivery in the observed campaign led to deployment of the StealC information stealer, with theft focused on developer credentials, browser-stored secrets, API keys, cloud credentials, and cryptocurrency wallets. Malware used in the operation reportedly incorporated LuaJIT, heavy virtual-machine-style obfuscation, and persistence via scheduled tasks disguised as legitimate driver-related activity. SmartLoader has been described as historically associated with fake installers used to spread infostealers and as evolving toward software supply-chain and AI-tooling ecosystems, including MCP-related infrastructure. Available reporting also notes indicators consistent with China-based operations, though public attribution details remain limited. The actor’s observed behavior is most consistent with financially motivated credential and data theft operations targeting high-value developer environments and downstream organizational access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.