SmokeLoader Malware Targets Ukraineâs Auto & Banking Sectors via Open Directories
ID: f787c8b6-9f03-50bf-b5d4-1f8e308be630
STIX ID: report--f787c8b6-9f03-50bf-b5d4-1f8e308be630
Feed Name: Hunt.io Blog
**Open directories were found hosting SmokeLoader binaries and financial-themed lure PDFs targeting Ukrainian organizations (automotive and banking sectors).** Hunt researchers identified multiple exposed servers with identical executables, associated C2 IPs and domains, and confirmed file hashes; the analysis details execution behavior (process injection, persistence location), dynamic DGA-derived Referer usage, and known SmokeLoader infrastructure, providing actionable IOCs for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
