SMOKY SPIDER
Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
SMOKY SPIDER is a cyber threat actor known for using SmokeLoader dropper to gain initial access to systems.
SMOKY SPIDER is a cyber threat actor identified in CrowdStrike's 2020 report as an operator of SmokeLoader. This actor targets organizations across various sectors with the objective of gaining initial access to their systems. Its primary TTP involves the use of the SmokeLoader dropper, known for advanced evasion techniques and acting as a loader for second-stage malware. Defenders should be vigilant against suspicious email attachments, monitor anomalous network requests, and strengthen endpoint detection solutions to block access to the C2 infrastructure associated with SmokeLoader.
Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
SMOKY SPIDER's primary TTP involves the use of the SmokeLoader dropper, known for advanced evasion techniques.
SMOKY SPIDER uses SmokeLoader as a loader for second-stage malware.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.