Smokeloader Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
October 23, 2025
Last Seen
June 24, 2026

Smokeloader is a malware family tracked across 9 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed October 23, 2025; most recent activity June 24, 2026.

Overview

Smokeloader is a Windows-based loader/malware family that serves as a delivery framework to deploy additional payloads (such as RATs and credential-stealers) onto compromised hosts. Its modular design and ability to fetch and execute extra modules from command-and-control infrastructures make it a significant facilitator in broader malware campaigns and persistence operations.

Related Threat Clusters

Recent Intelligence Reports

  • StealC you later: Proofpoint and IBM X — Ibm · June 24, 2026
  • Police cleans nearly 15,000 SocGholish — Bleepingcomputer · June 18, 2026
  • Infostealing Malware Remains Top Threat To Healthcare — www.techtarget.com · May 7, 2026
  • Formbook infostealer deployed in clandestine phishing campaigns | brief — Scworld · April 21, 2026
  • Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection — Infosecurity-Magazine · April 20, 2026
  • LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems — Acronis · February 12, 2026
  • Over 10,000 SystemBC Botnet Infections Identified Globally — Technadu · February 4, 2026
  • Interpol sweep takes down cybercrooks in 19 countries — Csoonline · December 24, 2025

CVSS v3.1 Breakdown