logo

SmokeLoader malware aimed at multiple Ukrainian industries, using bug in file archiver

ID: 95d72be6-250e-506f-a5b1-8f32e6fbd17a

STIX ID: report--95d72be6-250e-506f-a5b1-8f32e6fbd17a

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2025-02-05

Date Updated: 2026-05-01

...
...

Researchers observed Russian-linked actors actively exploiting a 7‑Zip vulnerability (CVE-2025-0411) to bypass Windows Mark-of-the-Web protections and deliver SmokeLoader via phishing attachments to Ukrainian government, transportation, healthcare, utility, manufacturing organizations and at least one major bank; the campaign (attributed to groups tracked as UAC-0006 with overlaps to FIN7) appears aimed at espionage and credential/data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.