SMOKEDHAM is a lightweight, highly adaptable .NET backdoor associated with UNC2465 and used in intrusions linked to DarkSide ransomware deployment. Reported delivery vectors include phishing emails, trojanized software installers, malvertising campaigns, and at least one supply-chain intrusion involving trojanized Nullsoft installers for SmartPSS and SVStation. The malware’s source code has been reported as embedded in its dropper as an encrypted string.
Observed capabilities include execution of arbitrary .NET commands and PowerShell commands received from command-and-control (C2), keylogging, screenshot capture, exfiltration of data to its C2 server, and host/account discovery via commands such as whoami as well as net.exe user and net.exe users. SMOKEDHAM has also been observed creating user accounts.
For persistence and post-compromise enablement, SMOKEDHAM has modified Windows Registry keys, including changes used for persistence, enabling credential caching for credential access, and facilitating lateral movement via RDP. In a documented UNC2465 intrusion, SMOKEDHAM established persistence for an ngrok-based remote access workflow by adding VirtualHost.vbs to HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run under the value WindNT. That activity supported tunneling UltraVNC traffic out of the victim environment through a legitimate ngrok binary renamed conhost.exe.
Network tradecraft described for SMOKEDHAM includes Base64-encoded C2 traffic. Infrastructure and staging noted in reporting include use of Google Drive and Dropbox to host files downloaded by victims via malicious links, and C2 hosts including max-ghoster1.azureedge[.]net, atlant20.azureedge[.]net, and skolibri13.azureedge[.]net. Additional reported indicators tied to SMOKEDHAM activity include the intermediate stage URL hxxp://sdoc[.]xyz/ID-508260156241, loader artifacts such as Gbdh7yghJgbj3bb.html, and related files including VirtualHost.vbs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC2465 now uses phishing emails to deliver DarkSide via the Smokedham .NET backdoor. Smokedham also supports the execution of arbitrary .NET commands, keylogging, and screenshot generation.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
APT3 has been known to create or enable accounts, such as support_388945a0 . ... APT5 has created Local Administrator accounts to maintain access ... DarkGate creates a local user account, SafeMode, via net user commands.
Numerous malware families and threat groups are described as achieving persistence by adding values under Run/RunOnce/Policies\Explorer\Run Registry keys or by placing shortcuts/files in the Windows Startup folder.
Operation Wocao enabled Wdigest by changing the HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest registry value from 0 (disabled) to 1 (enabled); Wizard Spider modified WDigest UseLogonCredential to 1 to force credentials to be stored in clear text in memory.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Operation Wocao enabled Wdigest by changing the HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest registry value from 0 (disabled) to 1 (enabled); Wizard Spider modified WDigest UseLogonCredential to 1 to force credentials to be stored in clear text in memory.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
Smokedham also supports the execution of arbitrary .NET commands, keylogging, and screenshot generation
Operation Wocao enabled Wdigest by changing the HKLM\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest registry value from 0 (disabled) to 1 (enabled); Wizard Spider modified WDigest UseLogonCredential to 1 to force credentials to be stored in clear text in memory.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
“actors used the following commands… to enumerate user accounts: net user >> %temp%\download; net user /domain >> %temp%\download … APT1 used the commands net localgroup, net user, and net group to find accounts… APT32 enumerated administrative users using the commands net localgroup administrators … OilRig has run net user, net user /domain, net group "domain admins" /domain …”
Aquatic Panda modified the victim registry to enable the RestrictedAdmin mode feature, allowing for pass the hash behaviors to function via RDP. SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP). SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
“APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads… EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads… Bumblebee has been downloaded… from OneDrive… Operation Spalax… used OneDrive and MediaFire to host payloads… Raspberry Robin… payloads… on Discord servers.”
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy backdoor used by UNC2465 for initial access, persistence, reconnaissance, lateral movement, and enabling extortion/ransomware deployment. It is delivered via trojanized installers (e.g., KeyStore Explorer, Angry IP Scanner), uses DLL side-loading and PowerShell obfuscation, manipulates Windows services (e.g., MSDTC) for persistence/privilege escalation, and communicates with C2 using techniques like domain fronting (e.g., Cloudflare Workers) to obscure traffic origins while executing arbitrary PowerShell commands and exfiltrating recon data.
Enterprise New Software: ... SMOKEDHAM
SMOKEDHAM is a .NET-based backdoor that provides remote access to compromised systems. It supports commands such as screen capture, keystroke logging, and execution of arbitrary PowerShell commands. It communicates with its C2 server using HTTPS and domain fronting, and uses RC4 encryption for command and data exchange. It is deployed via a PowerShell dropper and is used for persistence, lateral movement, and credential harvesting.
Smokedham is a .NET backdoor used to deliver DarkSide ransomware and provides capabilities including arbitrary .NET command execution, keylogging, and screenshot capture.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.