CLICKSMOKE is a multi-tenant malware-as-a-service platform used to deliver information-stealing malware. Documented tenants include Smokest and aero, which shared the same backend, schema, and infrastructure while using distinct build identifiers and delivery configurations. The platform has been observed shifting delivery methods from a PowerShell-based ClickFix-style chain to an MSI-based installer chain, indicating ongoing operator development and adaptation. Observed tradecraft includes initial access through scripted or installer-based malware delivery, followed by staged execution using PowerShell, additional tooling installation, and retrieval of a JavaScript loader that deploys a browser-credential stealer. The malware has been reported to target credentials from more than 20 browsers, enumerate numerous antivirus products, fingerprint infected hosts, maintain persistence through user-level autorun mechanisms, and repeatedly poll command-and-control infrastructure. These behaviors support capabilities in initial access, credential theft, persistence, defense evasion, and post-exploitation, with exfiltration implied by the infostealer mission. The platform appears to support multiple operators or customers rather than a single actor. Russian-language build metadata has been observed in one tenant context, and additional operator-side handles have been exposed in installer metadata. High-confidence attribution to a specific state or organization is not established, but available evidence supports operation from or by actors linked to Russia. The dominant motivation is financial, based on the platform's role in credential theft and infostealer deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.