Netskope Threat Labs

Smoke Loader

ATP Sandbox Adv. HeuristicsNetskope IPS

Smoke Loader is a malicious bot application used to load other malware, seen in the wild since at least 2011 with many different payloads over its lifetime. It is notorious for its use of deception and self protection techniques, and it ships with several plugins that extend its capabilities.

First seen
February 2022
Last seen
October 2026
DofoilSmokeLoaderSmokeloader

14 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1083File and Directory Discovery

TA0009 Collection

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Downloader.SmokeLoader
ByteCode-MSIL.Trojan.Smokeloader
ByteCode-MSIL.Trojan.SmokeLoader
Document-HTML.Trojan.SmokeLoader
Script-JS.Trojan.Smokeloader
Script-JS.Trojan.SmokeLoader
Script-PowerShell.Backdoor.SmokeLoader
Script-PowerShell.Trojan.Smokeloader
Script-WScript.Backdoor.SmokeLoader
Script-WScript.Trojan.Smokeloader