logo

Unit 42 Collaborative Research With Ukraine’s Cyber Agency To Uncover the Smoke Loader Backdoor

ID: 408659be-5683-5eb8-8f0e-34aa3e771393

STIX ID: report--408659be-5683-5eb8-8f0e-34aa3e771393

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-03-19

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 summarizes collaborative research with Ukraine's State Cyber Protection Centre (SCPC SSSCIP) on a surge of Smoke Loader (Dofoil/Sharik) activity attributed to the UAC-0006 group from May–December 2023; the report documents 23 phishing-driven waves delivering Smoke Loader (a Windows backdoor/loader with infostealing capabilities) to financial institutions and government organizations in Ukraine, describes secondary payloads and attack chains, and provides mitigation guidance and detection coverage recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.