Unit 42 Collaborative Research With Ukraine’s Cyber Agency To Uncover the Smoke Loader Backdoor
ID: 408659be-5683-5eb8-8f0e-34aa3e771393
STIX ID: report--408659be-5683-5eb8-8f0e-34aa3e771393
Feed Name: Palo Alto Networks Unit 42
Unit 42 summarizes collaborative research with Ukraine's State Cyber Protection Centre (SCPC SSSCIP) on a surge of Smoke Loader (Dofoil/Sharik) activity attributed to the UAC-0006 group from May–December 2023; the report documents 23 phishing-driven waves delivering Smoke Loader (a Windows backdoor/loader with infostealing capabilities) to financial institutions and government organizations in Ukraine, describes secondary payloads and attack chains, and provides mitigation guidance and detection coverage recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
