logo

SmokeLoader Malware Targets Ukraine’s Auto & Banking Sectors via Open Directories

ID: f787c8b6-9f03-50bf-b5d4-1f8e308be630

STIX ID: report--f787c8b6-9f03-50bf-b5d4-1f8e308be630

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

**Open directories were found hosting SmokeLoader binaries and financial-themed lure PDFs targeting Ukrainian organizations (automotive and banking sectors).** Hunt researchers identified multiple exposed servers with identical executables, associated C2 IPs and domains, and confirmed file hashes; the analysis details execution behavior (process injection, persistence location), dynamic DGA-derived Referer usage, and known SmokeLoader infrastructure, providing actionable IOCs for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.