Distribution of SmokeLoader Targeting Ukrainian Government and Companies
ID: 4e4af257-8307-5a81-9e4c-c226a9b1ddf0
STIX ID: report--4e4af257-8307-5a81-9e4c-c226a9b1ddf0
Feed Name: ASEC
AhnLab ASEC observed a SmokeLoader malspam campaign targeting Ukrainian government bodies and various organizations using invoice-themed emails with nested 7z/ZIP archives containing an SFX executable that spawns a decoy PDF and a BAT to run SmokeLoader (renamed with a .pdf extension). SmokeLoader injects into explorer.exe, persists under %AppData% as "ewuabsi", and contacts multiple C2 domains (listed in the report) to download additional modules or ransomware such as LockBit; the report includes MD5 hashes and vendor detection names for the samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
