Smoke Loader - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:28:52 UTC Home > List all groups > List all tools > List all groups using tool Smoke Loader Tool: Smoke Loader Names Smoke Loader SmokeLoader Smoke Dofoil Sharik Category Malware Type Botnet, Downloader, Miner Description The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. SmokeLoader, in addition to being used to download standalone coinminers, is available on underground markets with a built-in coinminer module for an additional fee. Information microsoft-spoils-its-campaign> MITRE ATT&CK Malpedia AlienVault OTX Last change to this tool card: 21 April 2025 Download this tool card in JSON format All groups using tool Smoke Loader Changed Name Country Observed APT groups TA530 [Unknown] 2016-Nov 2016 Other groups https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0fb51f1-5f2e-4efc-a59f-70ca9a5f0744 Page 2 of 3 Bamboo Spider, TA544 [Unknown] 2016-Apr 2022   Smoky Spider [Unknown] 2011-Apr 2019   TA516 [Unknown] 2016-Feb 2020   4 groups listed (1 APT, 3 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0fb51f1-5f2e-4efc-a59f-70ca9a5f0744 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0fb51f1-5f2e-4efc-a59f-70ca9a5f0744 Page 3 of 3