Smoke and Fire – Smokeloader Historical Changes and Trends

Botconf 2022
2023-04-23 | 16:45 – 17:25

Marcos Alvares 🗣

Smokeloader (aka Sharik or SmokeBot) turned 10 in 2021! Few malware families make to this mark without collapsing or getting caught by law enforcement. For over a decade, Smokeloader has been deployed as part of distribution schemes of many high-profile financially motivated malware families, such as Dridex, Trickbot, ISFB and SilentNight. Its simplicity and business model have contributed to this longevity. This presentation intends to provide (i) a technical overview on key changes implemented over the past 10 years, (ii) statistics on customers and infrastructure and (iii) highlights on tactics that helped smokeloader survive all this time.

Slides Icon


Scroll to Top