Threat researchers reported a malware campaign that used fake privacy-tool websites to trick users into downloading trojanized Windows installers that delivered SmokeLoader. Identified lure domains included privacytools[.]xyz, privacytoolsforyou[.]site, privacmytools[.]site, and privacy-tools-for-you-777[.]com, with one malicious installer tracked by SHA-256 47906fc0ac7d3be54c62933e5f66a285cd34f161ce1d8a1bbdf80dc2e1df1441. The operation relied on spoofed software-download pages and rogue file-hosting sites designed to resemble legitimate privacy software distribution.
Investigators linked the activity to a broad and frequently changing infrastructure that included at least 26 fake privacy-tool domains, 18 related file-hosting domains, numerous command-and-control URLs across TLDs such as .space, .ru, .site, .xyz, and .com, and shared bulletproof hosting. Some file-hosting domains also appeared to serve as SmokeLoader C2 nodes, while additional indicators included DNS-linked IP addresses and RSA key material associated with encrypted malware communications, underscoring a coordinated malware delivery and control network.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The domains privacytoolzforyou-7000[.]com and privacytoolzfor-you7000[.]com were registered on 19 November 2021 as part of the fake privacy-tool campaign. Silent Push linked them to the broader malicious domain cluster.
Silent Push reported that the fake privacy-tool campaign switched to its current bulletproof hosting provider sometime in September 2021. This marked an infrastructure change affecting both the fake software sites and related rogue file-hosting domains.
Silent Push found related fake privacy-tool domains dating back as early as June 2021, indicating the malware distribution campaign was already active by then. The domains were assessed as part of the same actor's infrastructure serving SmokeLoader.
Silent Push identified at least 26 fake privacy-tool domains and 18 similarly patterned rogue file-hosting domains, assessing that they were very likely operated by the same actor. It also found that some of the file-hosting domains appeared to function as SmokeLoader command-and-control infrastructure.
Proofpoint identified fake download domains including privacytools[.]xyz, privacytoolsforyou[.]site, and privacmytools[.]site, along with a large rotating set of command-and-control URLs, DNS infrastructure, and RC4 key values. The disclosure documented an organized malware delivery and C2 operation using trojanized privacy-tool downloads.
Silent Push reported that privacy-tools-for-you-777[.]com had been registered the previous day and was live masquerading as a privacy tool website. Its installer download was identified as malware, and URLhaus reported files from the same URL as SmokeLoader.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.