Smoke Loader

MITRE
Tipo Malware:
Other
Prima attivita:
Unknown
Ultima attivita:
Unknown
Dettagli:

[Smoke Loader](https://attack.mitre.org/software/S0226) is a malicious bot application that can be used to load other malware.
[Smoke Loader](https://attack.mitre.org/software/S0226) has been seen in the wild since at least 2011 and has included a number of different payloads. It is notorious for its use of deception and self-protection. It also comes with several plug-ins. (Citation: Malwarebytes SmokeLoader 2016) (Citation: Microsoft Dofoil 2018)

Tecniche Associate (14)
ID ATT&CK Tattiche
T1027.013 Encrypted/Encoded File -
T1053.005 Scheduled Task -
T1055 Process Injection -
T1055.012 Process Hollowing -
T1059.005 Visual Basic -
T1071.001 Web Protocols -
T1083 File and Directory Discovery -
T1105 Ingress Tool Transfer -
T1114.001 Local Email Collection -
T1140 Deobfuscate/Decode Files or Information -
T1497.001 System Checks -
T1547.001 Registry Run Keys / Startup Folder -
T1552.001 Credentials In Files -
T1555.003 Credentials from Web Browsers -
Alias (105)
Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil Dofoil
Metadata
ID: 48
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00