ATT&CKSoftwareSmoke Loader

Smoke Loader

S0226

Malware.View on attack.mitre.org

About this malware

Smoke Loader is a malicious bot application that can be used to load other malware.
Smoke Loader has been seen in the wild since at least 2011 and has included a number of different payloads. It is notorious for its use of deception and self-protection. It also comes with several plug-ins.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Smoke Loader uses a simple one-byte XOR method to obfuscate values in the malware.

T1053.005
Scheduled Task

Smoke Loader launches a scheduled task.

T1055
Process Injection

Smoke Loader injects into the Internet Explorer process.

T1055.012
Process Hollowing

Smoke Loader spawns a new copy of c:\windows\syswow64\explorer.exe and then replaces the executable code in memory with malware.

T1059.005
Visual Basic

Smoke Loader adds a Visual Basic script in the Startup folder to deploy the payload.

T1071.001
Web Protocols

Smoke Loader uses HTTP for C2.

T1083
File and Directory Discovery

Smoke Loader recursively searches through directories for files.

T1105
Ingress Tool Transfer

Smoke Loader downloads a new version of itself once it has installed. It also downloads additional plugins.

T1114.001
Local Email Collection

Smoke Loader searches through Outlook files and directories (e.g., inbox, sent, templates, drafts, archives, etc.).

T1140
Deobfuscate/Decode Files or Information

Smoke Loader deobfuscates its code.

T1497.001
System Checks

Smoke Loader scans processes to perform anti-VM checks.

T1547.001
Registry Run Keys / Startup Folder

Smoke Loader adds a Registry Run key for persistence and adds a script in the Startup folder to deploy the payload.

T1552.001
Credentials In Files

Smoke Loader searches for files named logins.json to parse for credentials.

T1555.003
Credentials from Web Browsers

Smoke Loader searches for credentials stored from web browsers.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Malwarebytes SmokeLoader 2016 Open source
    Hasherezade. (2016, September 12). Smoke Loader – downloader with a smokescreen still alive. Retrieved March 20, 2018.
  2. Microsoft Dofoil 2018 Open source
    Windows Defender Research. (2018, March 7). Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign. Retrieved March 20, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.