Smoke is a modular Windows malware family first identified in 2011 and commonly characterized as a downloader or loader used to retrieve and execute additional payloads. It has been associated with financially motivated cybercrime operations and has appeared both as a standalone malware service and as a component within broader multi-stage intrusion chains. Reported use cases include delivery of secondary malware, information theft, process injection, and defense-evasion activity to support follow-on monetization such as credential theft, proxy-bot deployment, cryptomining, or ransomware.
Smoke has been observed injecting code into legitimate Windows processes, including explorer.exe, to conceal execution and maintain access to command-and-control infrastructure. In documented infections it communicated with remote servers over HTTP, downloaded or facilitated execution of additional malware, and used PowerShell to weaken host defenses by adding antivirus exclusions. It has also been observed abusing scheduled tasks to achieve persistence and launch follow-on payloads at boot with elevated privileges. In at least one analyzed infection chain, Smoke activity supported deployment of miner components and operated alongside multiple commodity stealers and ransomware on the same host.
The malware has also been linked to criminal distribution campaigns using phishing-themed infrastructure and malicious documents, and it has been noted as one of several third-party malware families manually modified by the Silence group. Across reporting, the strongest consistent characterization is that Smoke is a modular Windows loader/downloader used in cybercrime ecosystems to establish execution, evade defenses, and deliver additional malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When needed, the group would also manually modify malware developed by other crooks, such as the Kikothac backdoor, the Smoke downloader, or the Undernet DDoS bot.
When the malicious code is executed, the file downloads the payload from http://google-document[.]co.za/doc/loader.exe. Signature analysis showed that the downloaded file is a Smoke loader sample.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader used in the later phase of the campaign, downloaded from attacker-controlled infrastructure as part of malware delivery experimentation.
A modular loader that injects code into explorer.exe, downloads or executes additional malware, modifies Defender exclusions, and establishes persistence via scheduled tasks while evading detection.
A modular loader that can download additional malware, steal information, inject into processes like explorer.exe, evade detection, and establish persistence via scheduled tasks and defense evasion.
A third-party downloader that the Silence group manually modified for use in its operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.