SmokeLoader malware aimed at multiple Ukrainian industries, using bug in file archiver
ID: 95d72be6-250e-506f-a5b1-8f32e6fbd17a
STIX ID: report--95d72be6-250e-506f-a5b1-8f32e6fbd17a
Feed Name: The Record from Recorded Future News
Threat Score
Researchers observed Russian-linked actors actively exploiting a 7‑Zip vulnerability (CVE-2025-0411) to bypass Windows Mark-of-the-Web protections and deliver SmokeLoader via phishing attachments to Ukrainian government, transportation, healthcare, utility, manufacturing organizations and at least one major bank; the campaign (attributed to groups tracked as UAC-0006 with overlaps to FIN7) appears aimed at espionage and credential/data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
