SmokeLoader is a long-running malware family and criminal service operated under a Malware-as-a-Service model, primarily functioning as a loader that enables follow-on malware delivery and broader intrusion activity. It has been associated with resilient command-and-control infrastructure that uses fast-flux DNS techniques to rotate proxy nodes and obscure backend systems, complicating IP-based disruption and takedown efforts. SmokeLoader has been publicly identified as part of the ransomware precursor ecosystem and was among the malware operations targeted during Operation Endgame in 2024 and 2025. SmokeLoader is used as a secondary-stage delivery mechanism within multi-malware intrusion chains and has appeared alongside other criminal tooling including BumbleBee, LummaStealer, Stealc, and remote-access components. In observed campaigns, it has supported post-compromise malware deployment rather than acting solely as the initial infection vector. Its infrastructure has remained active even when adjacent delivery channels were disrupted, indicating operational resilience and continued maintenance. The malware’s operators or associated distributors are linked to Russian-speaking cybercriminal activity at a high level of confidence. Reporting ties SmokeLoader to the broader Russia-based cybercrime ecosystem, and source-geography evidence supports Russia as the primary operating environment. Historical infrastructure overlap or reuse has also been noted between SmokeLoader-associated systems and LockBit-hosting infrastructure, suggesting either cooperation, shared service providers, or recycled criminal infrastructure, though the precise relationship is not established with high confidence. SmokeLoader is best understood as a criminal enablement platform within the malware delivery supply chain: it supports initial or follow-on access, persistence of attacker-controlled communications through hidden infrastructure, and delivery of additional payloads used for credential theft, remote access, defense evasion, and later-stage compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses fast-flux infrastructure to rotate C2 domains and obscure command-and-control infrastructure.
Secondary loader used in the Shanya campaign as a backup delivery channel. Its infrastructure remained live, with multiple C2 domains resolving to Google Cloud infrastructure and one domain registered through a Russian registrar.
Generic backdoor malware operation whose infrastructure was historically tied to a server later used by LockBit, suggesting possible server rental, acquisition, or cooperation between operators.
Established malware operator brand referenced in forum OPSEC discussions following law enforcement action.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.