logo

Smoke Loader poses as an Office plugin

ID: 9a2b10fd-cde9-566d-828e-ee0315fc4daa

STIX ID: report--9a2b10fd-cde9-566d-828e-ee0315fc4daa

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2015-08-27

Date Updated: 2026-04-19

Author: Łukasz Siewierski

...
...

This report describes a targeted Smoke Loader malware campaign against Polish users that used a fake Microsoft Office browser-plugin installer to drop a Visual Basic-packed payload (DONEAPP.EXE). The loader establishes persistence in %APPDATA%, tests connectivity via msn.com, contacts an encrypted C2 (cannedgood.eu), and supports plugins including Rootkit.dll (hooks NtEnumerateValueKey and NtQueryDirectoryFile to hide autorun registry keys and files) and Faker.dll (intercepts and alters DNS responses), enabling stealthy data-collection and redirection for phishing; the infrastructure was quickly abandoned after publicity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.