SMOKEDHAM

S0649

Malware.View on attack.mitre.org

About this malware

SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021; it has been used by at least one ransomware-as-a-service affiliate.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1027.009
Embedded Payloads

The SMOKEDHAM source code is embedded in the dropper as an encrypted string.

T1033
System Owner/User Discovery

SMOKEDHAM has used whoami commands to identify system owners.

T1041
Exfiltration Over C2 Channel

SMOKEDHAM has exfiltrated data to its C2 server.

T1056.001
Keylogging

SMOKEDHAM can continuously capture keystrokes.

T1059.001
PowerShell

SMOKEDHAM can execute Powershell commands sent from its C2 server.

T1071.001
Web Protocols

SMOKEDHAM has communicated with its C2 servers via HTTPS and HTTP POST requests.

T1082
System Information Discovery

SMOKEDHAM has used the systeminfo command on a compromised host.

T1087.001
Local Account

SMOKEDHAM has used net.exe user and net.exe users to enumerate local accounts on a compromised host.

T1090.004
Domain Fronting

SMOKEDHAM has used a fronted domain to obfuscate its hard-coded C2 server domain.

T1098.007
Additional Local or Domain Groups

SMOKEDHAM has added user accounts to local Admin groups.

T1102
Web Service

SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links.

T1105
Ingress Tool Transfer

SMOKEDHAM has used Powershell to download UltraVNC and ngrok from third-party file sharing sites.

T1112
Modify Registry

SMOKEDHAM has modified registry keys for persistence, to enable credential caching for credential access, and to facilitate lateral movement via RDP.

T1113
Screen Capture

SMOKEDHAM can capture screenshots of the victim’s desktop.

T1132.001
Standard Encoding

SMOKEDHAM has encoded its C2 traffic with Base64.

View all 21 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. FireEye SMOKEDHAM June 2021 Open source
    FireEye. (2021, June 16). Smoking Out a DARKSIDE Affiliate’s Supply Chain Software Compromise. Retrieved September 22, 2021.
  2. FireEye Shining A Light on DARKSIDE May 2021 Open source
    FireEye. (2021, May 11). Shining a Light on DARKSIDE Ransomware Operations. Retrieved September 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.