HomeSecuritySmokeLoader: New capabilities for data theft and DoS attacks

SmokeLoader: New capabilities for data theft and DoS attacks

SmokeLoader , which first appeared in 2011, has evolved into a dangerous modular malware loader , designed to deliver a variety of secondary payloads, including trojans, ransomware, and stealing. credential tools

SmokeLoader: New capabilities for data theft and DoS attacks

Following the Endgame police operation that disrupted many malicious campaigns in mid-2024, the loader resurfaced in early 2025 with two distinct versions: version 2025 alpha and version 2025. Both versions address previous performance issues , enhance evasion capabilities, and extend the plugin framework that enables various malicious activities.

Zscaler researchers noted that these updates allow SmokeLoader to operate more discreetly and effectively on compromised computers.

See also: Sidewinder APT exploits protests in Nepal to distribute malware

SmokeLoader: How does the malware work?

Initially, the main function of SmokeLoader was to inject a module into Windows Explorer for continuous execution and communication with command and control (C2) servers. The stager, which is responsible for this injection, did not perform proper checks beforehand and continuously injected new copies of the module, causing severe performance degradation.

SmokeLoader: New capabilities for data theft and DoS attacks

Zscaler analysts discovered that the 2025 alpha version introduced a mutex check in the stager, terminating the injection process if the mutex already exists. This mutex generation algorithm , which generates a random alphanumeric string (based on the first four bytes of the bot ID), prevents repeated injections and conserves system resources.

Researchers noted that in addition to the stability of the loader, plugin framework has also matured significantly. Operators can optionally deploy modules that collect browser credentials, hijack sessions, perform DoS attacks, and mine cryptocurrency. Each plugin is delivered as a secondary payload, activated based on configuration flags received from the C2. This flexibility allows malicious users to tailor payloads to specific goals (from data extraction in targeted espionage to volumetric DoS in extortion campaigns).

Infection Mechanism and Persistence

The SmokeLoader infection chain begins with an email identifier or exploit kit that delivers the stager as a shellcode-packed executable. Once executed, the stager resolves Windows API dependencies based on hashes, decrypts code blocks with hardcoded offsets, and injects the main module into the explorer.exe process using 64-bit shellcode.

See also: Mustang Panda develops SnakeDisk USB Worm to distribute Yokai Backdoor

Once in explorer.exe, the main module creates a scheduled task for persistence, named “MicrosoftEdgeUpdateTaskMachine%hs,” where the placeholder is the first 16 characters of the bot ID. This contrasts with previous versions that used “Firefox Default Browser Agent %hs,” demonstrating the attacker’s attempt to impersonate legitimate update services.

SmokeLoader: New capabilities for data theft and DoS attacks

After establishing persistence, the main module creates the same mutex to avoid repeated execution and begins communicating with the C2 servers using an updated protocol that includes a four-digit CRC32 checksum. This checksum is calculated on the payload starting at offset six, ensuring integrity and preventing simple network sniffing.

Researchers say another change in the new SmokeLoader variants has to do with response handling: the original four-byte command length field is now XOR-obfuscated with the RC4 key, complicating the matching of static signatures.

See also: Phoenix RowHammer: Bypasses advanced DDR5 memory protections

Throughout this process, Zscaler analysts observed that SmokeLoader's network communications systematically mimicked legitimate browser user agents and TLS handshakes, blending malicious traffic with normal web browsing.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

By incorporating the above improvements in both the stager and the main module (along with flexible plugins), SmokeLoader remains a powerful threat, enabling data theft and DoS attacks under a single, customizable framework.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS