PULSE NAME
Technical Analysis of SmokeLoader Version 2025
WHITE AlienVault 2025-09-16 Modified: 2025-10-16
40
IOCs
MEDIUM VOLUME
SmokeLoader, a modular malware loader active since 2011, has resurfaced with new versions in 2025 after Operation Endgame suppressed its activity. The latest variants, 2025 alpha and 2025, include bug fixes and improvements to evade detection. Key changes include a new mutex check in the stager, modified mutex name generation, and updates to the main module. The network protocol has been slightly adjusted in version 2025, and the scheduled task name for persistence has been updated. These versions fix performance issues and include additional anti-analysis measures. Despite efforts to dismantle it, SmokeLoader continues to evolve and is used by multiple threat groups.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SmokeLoader Smoke Loader - S0226 Dofoil Smoke Loader - S0226 Dofoil
Indicators of Compromise (9 / 40 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 15b00779bb5d457e76712ec3dd196c46 2025-09-16
FileHash-MD5 2092e90739b3c899d1a4a45e3840bf2c 2025-09-16
FileHash-MD5 78748c62cecdba6c56d5ed4de64036ed 2025-09-16
FileHash-MD5 89212a84f1b81d0834edb03b16a9db49 2025-09-16
FileHash-MD5 9edbf77e52249cc7c179ed1334847cdb 2025-09-16
FileHash-MD5 d20d31a0e64cf722051a8fb411748913 2025-09-16
FileHash-MD5 e1484b39c54994e20a34d96f2322a103 2025-09-16
FileHash-MD5 290d9e7e033e0b42baca7d072bb5959d 2025-09-16
FileHash-MD5 f2b790302bfb0e7f97f36a387eaeb227 2025-09-16