Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries.
The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Talos said most of the analyzed Salfram-packed samples dated from January 2020 onward, reflecting increased observed activity during that period. The campaigns used contact-form abuse and malicious documents hosted on legitimate services such as Google Drive.
Cisco Talos reported that analyzed malware samples using the distinctive "Salfram" crypter had compiler or debug timestamps ranging from April 2019 to August 2020, indicating the crypter was in use by April 2019. The crypter was used across campaigns delivering malware including Gozi ISFB, ZLoader, SmokeLoader, Oski, AveMaria, and Cobalt Strike.
Cyble described SystemBC as a proxy and remote administrative tool first seen in 2019. The report noted it had since been used by multiple threat actors, including in ransomware attacks.
Cyble Research and Intelligence Labs reported a campaign in which SmokeLoader delivered SystemBC, RecordBreaker, and the new Laplas Clipper malware. The firm said it identified more than 180 Laplas-related samples over the previous two weeks, indicating broad recent deployment.
Cyble reported that the FBI and law enforcement partners in the Netherlands and Italy dismantled Raccoon Infostealer infrastructure and took its existing version offline. This preceded the emergence of RecordBreaker as a revived version of Raccoon Stealer 2.0.
Cyble stated that alleged Raccoon Stealer operator Mark Sokolovky was arrested by Dutch authorities in March. The report cited the arrest in the context of RecordBreaker being a revived version of Raccoon Stealer 2.0.
Cisco Talos uncovered ongoing email campaigns that used website contact forms and Google Drive-hosted malicious Office documents to infect victims. Talos linked the campaigns through the shared "Salfram" crypter used in initial payloads despite delivery of multiple malware families.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.cyble.com
Open sourceblog.talosintelligence.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.