The website of Crystal Finance Millennium, a Ukrainian vendor of medical and accounting software, was compromised and used to deliver multiple malware families, including Smoke Loader, Chthonic, and the PSCrypt ransomware. Malicious files were hosted on cfm.com.ua and supported by additional domains, with payloads dropped into %AppData% and outbound connections made to external command-and-control infrastructure. After the compromise was identified, the hosting provider took the site offline.
The incident linked a well-known downloader to a broader multi-stage infection chain. Smoke Loader has remained active as a malware delivery tool and has been observed fetching follow-on payloads, establishing persistence through Windows Run registry keys, contacting decoy and command-and-control domains, and enabling delivery of additional malware families. In the Crystal Finance Millennium intrusion, PSCrypt encrypted files with the .pscrypt extension, demanded 3,500 Hryvnia, cleared event logs, and removed RDP-related files and registry keys, reinforcing concerns that the compromise formed part of a targeted campaign against Ukrainian organizations.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On 2017-11-02, analysts observed Sharik/Smoke Loader downloaded from 89.38.98[.]150, which then fetched Neutrino malware and ultimately multiple Lethic spambot binaries. The chain included persistence via Run keys and communications with eeaglelifedd[.]com and a .bit domain.
Payment history tied to PSCrypt ransom activity led the researcher to conclude the Crystal Finance Millennium website had been compromised by 15 August, and possibly as early as 14 August. The compromised site was then used to distribute Smoke Loader, Chthonic, and PSCrypt.
Malwarebytes published analysis describing Smoke Loader as a still-active downloader malware family. This establishes prior activity of one of the malware families later seen in the Crystal Finance Millennium compromise.
After the compromise was identified, the hosting provider took the Crystal Finance Millennium website offline. The site had been serving multiple malware families from paths on cfm.com.ua.
The Crystal Finance Millennium analysis states that Chthonic had been observed in June targeting a government institution in Ukraine. This is cited as prior Ukraine-focused activity involving one of the malware families served through the compromised site.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
malware-traffic-analysis.net
Open sourcebartblaze.blogspot.com
Open sourceblog.malwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.