Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
According to 360 NetLab, the (relatively) ancient malware downloader has enjoyed a slow burn on the black market, where malicious actors can pick up a customized copy for $850. While other researchers have identified various aspects of the threat, 360 NetLab took aim at the malware’s admin panel, which offers support for multiple plugins and functions — such as FORM GRAB, BOT LIST, KEYLOGGER and more — designed to help attackers successfully infiltrate targeted devices. The flexibility of Smoke Loader remains its biggest appeal; it was among the top 10 malware threats detected by Check Point in December 2018. It’s the first time a second-stage downloader has made the list, and may indicate a coming shift in the threat profiles of typical malware attacks. Smoke Loader has been observed to distribute DoppelPaymer ( Doppel Spider ), TinyLoader ( Tiny Spider ), DanaBot ( Scully Spider, TA547 ), BokBot ( Lunar Spider ), Zeus Panda ( Bamboo Spider, TA544 ) and TrickBot ( Wizard Spider, Gold Blackburn ).
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database