Smokest is a Deno-based remote access Trojan (RAT) observed as a follow-on payload in a malware distribution campaign that used counterfeit installers and plugins hosted on GitHub and SourceForge and promoted through compromised YouTube channels with AI-generated videos. The lures impersonated popular software including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. In the reported infection chain, victims were instructed to run terminal or cmd commands that downloaded an MSI installer or PowerShell script, which then abused legitimate tools including Scoop, WinGet, and the Deno runtime to execute staged JavaScript payloads. DinDoor, a Deno-based backdoor, was delivered first and then downloaded additional payloads including Smokest. Researchers stated the RAT has previously been referred to as "Smokest" based on a config value, but they did not confirm a formal name or attribution; code similarities, shared infrastructure, and similar commenting style suggested the DinDoor and Smokest developers may be the same person or team.
Smokest supports both HTTP and WebSocket command-and-control communications. Reported capabilities include collecting system information; executing arbitrary commands, PowerShell scripts, and shellcode; capturing screenshots; launching and terminating processes; managing files; establishing SOCKS5 proxy tunnels over WebSocket; and implementing bidirectional remote control functionality. It also contains stealer functionality targeting more than 50 cryptocurrency wallet extensions and 10 wallet applications, including Atomic Wallet, Exodus, Electrum, and ByteCoin. The malware steals data from Chromium-based browsers including Chrome, Chromium, Brave, Edge, Opera, Vivaldi, CentBrowser, Kometa, Orbitum, 360Browser, Chromodo, and Avast Browser, and also targets Telegram, Discord, and Lightcord. Additional reported behavior includes recording or modifying clipboard contents and exfiltrating data from files with specific extensions.
A notable capability is a peer-to-peer screen streaming mode designed to reduce network visibility: Smokest silently launches Microsoft Edge, connects through the Chrome DevTools Protocol, injects a WebRTC page, and streams the victim's screen directly to the operator. Reported command names include exec, exec-ps, exec-sc, sysinfo, screenshot, and stealer. Mentioned C2-related paths include /health, /token, and /vnc/agent/, and configuration data was described as Base64-encoded and transmitted as an authorization token. Infrastructure associated in the reporting included domains such as ms-telemetry-gateway-us.com, dakatawebstick.com, and cf-proxy.cloud-analytics-services.workers.dev, as well as IPs including 23.227.196.107 and 45.137.99.121.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious repositories ask visitors to open a terminal and paste a command that downloads an MSI installer or a PowerShell script from GitHub.
The RAT gives operators wide control of an infected machine. It can execute arbitrary commands
List folders, files and exfiltrate content from files with specific extensions
It can execute arbitrary commands and PowerShell scripts, capture screenshots
reports system details to a command-and-control server, and pulls down further payloads.
To stream live video of a victim’s screen, the RAT silently launches Microsoft Edge, connects to it through the Chrome DevTools Protocol, and injects a WebRTC page.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Deno-based remote access trojan used as a follow-on payload. It can execute commands and PowerShell scripts, capture screenshots, manage files, launch or kill processes, open SOCKS5 proxy tunnels, steal data from cryptocurrency wallets and Chromium-based browsers, and stream a victim's screen by abusing Microsoft Edge, Chrome DevTools Protocol, and WebRTC.
A Deno-based remote access trojan delivered by DinDoor. It supports command execution, PowerShell execution, system reconnaissance, screenshot capture, file theft, browser and wallet data theft, Telegram/Discord theft, clipboard manipulation, SOCKS5 proxying, WebSocket communications, and a peer-to-peer streaming mode that abuses Microsoft Edge and WebRTC to hide traffic.
A Deno-based remote access trojan with built-in stealer capabilities. It supports command execution, screenshots, browser and wallet theft, Telegram/Discord data theft, SOCKS5 tunneling, VNC-like remote control, and a peer-to-peer streaming mode using Microsoft Edge and WebRTC to hide traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.