Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Malsmoke

Also known as: tracked as, APT28, Pawn Storm, Fancy Bear, AMOS, BlackCat, fields, Sednit, Zeus

Description

Malsmoke first surfaced in late 2019 and has evolved from traditional exploit‑kit operations—using Fallout—to sophisticated social engineering via fake Java updates and adult content lures. The actor delivers Zloader through high‑traffic malvertising campaigns, then escalates to ransomware deployment (Zloader, BlackCat/ALPHV, Cl0p, Ryuk) by leveraging shared bulletproof hosting and DGA‑generated C2 domains. Operationally, Malsmoke employs a hybrid toolset that combines commercial frameworks such as Cobalt Strike and Mythic with open‑source exploit tools like Metasploit, Havoc, and Sliver. Initial access is often achieved through legitimate remote management software (Atera) or SSH tunneling, followed by credential‑guessing attacks, LLMNR/NBT-NS poisoning, and SMB relay for lateral movement. Persistence tactics include DLL injections into digitally signed system libraries, regsvr32-based execution of custom DLLs, mshta.exe usage, and startup‑folder scripts. Defense evasion is achieved via obfuscated payloads (T1027), encrypted files, PowerShell scripting, and exploitation of Microsoft’s digital signature verification. Financial gain remains the primary motivation, as evidenced by recurring ransomware extortion attempts that encrypt victim data for ransom payments.

Goals & Targeting

Targeted Sectors

Financial services
Non profit
Manufacturing
Defense

Targeted Countries / Regions

CN
US
CA

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 days ago

Executive Summary

Malsmoke is a financially motivated threat actor that targets predominantly Japanese users through malvertising on adult sites, delivering malware such as Zloader and later ransomware payloads. The group shares infrastructure with several ransomware affiliates, uses a mix of commercial and open-source post‑exploitation frameworks, and frequently leverages legitimate remote management software for initial access. Its campaigns combine advanced lateral movement techniques, DLL injection into signed libraries, and DGA-based C2 domains to evade detection while maintaining a rapid operational tempo.

Goals & Targeting

Malsmoke’s strategic objective centers on maximizing financial returns through ransomware extortion while masking its footprints via shared infrastructure. It selectively targets sectors with high-value data—financial services, defense contractors, manufacturing firms, and nonprofits—focusing on Japanese organizations but also extending operations to the US, Canada, and China. By leveraging broad geographic IPs in ad networks and low‑cost hosting, the actor can maintain a high operation volume with reduced attribution risk.

Enhanced Description

Key Capabilities

  • Uses SSH tunneling for remote access and reconnaissance
  • Shares infrastructure (bulletproof hosting and DGA domains) with Cl0p, BlackCat/ALPHV, Black Basta, Ryuk
  • Implements post‑exploitation C2 via commercial tools (Cobalt Strike, Mythic) and open‑source exploits (Metasploit, Havoc, Sliver)
  • Deploys ransomware payloads that encrypt victim data for monetization
  • Initial access through legitimate RMM software such as Atera
  • Injects malicious DLLs into digitally signed system libraries using Microsoft signature evasion
  • Executes custom DLLs via mshta.exe and regsvr32 with persistent startup scripts
  • Leverages LLMNR/NBT-NS poisoning and SMB relay for lateral movement
  • Performs credential stuffing and password guessing attacks
  • Utilizes obfuscated or encrypted payloads, PowerShell scripts, and C&C over TLS

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Lateral Movement
Command and Control
Impact

ATT&CK Techniques

T1078
T1078.004
T1078.002
T1086
T1105
T1110.001
T1110.003
T1110.004
T1117
T1027.001
T1041
T1059
T1059.001
T1531
T1547.009
T1557
T1557.001
T1486
T1499.004
T1569
T1569.002
T1588.001
T1204.002

Software / Tooling

Cobalt Strike
Mythic
Havoc
Sliver
Metasploit
Brute Ratel
Zloader
BlackCat/ALPHV
Cl0p
Black Basta
Ryuk
Atera
Smoke Loader
Adwind

Campaigns & Victims

Malsmoke operates with a rapid, opportunistic cadence, frequently launching new batches of adult‑content malvertising over several days and quickly pivoting to ransomware deployment once footholds are established. The actor shows a preference for high‑traffic but low‑security environments (adult sites in Japan) that allow wide distribution of its payloads while staying under the radar. Infrastructure reuse—with shared bulletproof hosting IPs and DGA domains—indicates deliberate collusion or outsourcing with other ransomware affiliates to dilute attribution. Victims are predominantly small‑to‑medium enterprises in finance, defense, nonprofit, and manufacturing sectors; however, any organization exposed on the actor’s malicious ad networks remains at risk.

IOC Patterns

  • ip-v4
  • file
  • domain
  • hash-md5

Recommended Actions

  • Block outbound traffic to known bulletproof hosting IPs such as 88.214.25.253 and associated DGA domains; use threat feeds to update firewall rules.
  • Detect and restrict usage of SSH services: enforce strong authentication, lock down default ports, monitor for anomalous fingerprint signatures (e.g., 55c658703c07d6344e325ea26cf96c3b).
  • Implement strict RMM access controls: vet installations of tools like Atera, apply least‑privilege policies and log all remote sessions.
  • Deploy endpoint detection that triggers on mshta.exe or regsvr32.exe invocations with non‑standard DLL arguments; quarantine suspicious processes immediately.
  • Enforce SMB security hardening (disable LLMNR/NBT-NS, enforce SMB signing, patch NetBIOS vulnerabilities) to mitigate relay attacks.
  • Use application whitelisting and real‑time monitoring of auto‑execution mechanisms such as startup folder scripts and Windows Service creation (T1547).
  • Implement ransomware detection solutions that alert on cryptographic file access patterns indicative of T1486 encryption activity.
  • Enforce MFA, account lockout policies, and password hygiene to counter credential stuffing and guessing attacks.
  • Apply network segmentation to limit lateral movement from compromised machines; deploy micro‑segmentation and zero‑trust principles.
  • Maintain an updated list of known malicious C2 frameworks (Cobalt Strike, Mythic, Metasploit) in security controls (sandboxing, sandbox monitoring).

Suggested Tags

Malsmoke
Ransomware
Malvertising
Adult Content Lures
Zloader
BlackCat/ALPHV
Cl0p
Ryuk
Black Basta
Bulletproof Hosting
LLMNR Poisoning
SMB Relay
DLL Injection
Digital Signature Evasion
Credential Access
Password Guessing
DGA-based C&C
Remote Management Software Abuse

Confidence Assessment

The compiled intelligence comes from multiple fragmented sources, providing a consistent picture of Malsmoke’s tactics, techniques and procedures but leaving notable gaps. While financial motive is strongly implied through ransomware activity, the actor’s exact operational timeline, attribution to specific geopolitical objectives, and comprehensive malware taxonomy remain uncertain. Further analysis of host footprints and code samples would increase confidence in the identified capabilities and tool associations.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. docs.rapid7.com — Cited by web research for: T1098
  2. www.group-ib.com — Cited by web research for: metasploit
  3. research.checkpoint.com — Cited by web research for: mshta
  4. www.trendmicro.com — Cited by web research for: SentinelOne
  5. www.group-ib.com — Cited by web research for: Agent Tesla

Intel Summary

25

Techniques

49

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

Critical Infrastructure
Backdoor / C2
APT
cybercrime
financial
Japan
malvertising
Zloader
Malsmoke
Ransomware
Malvertising
Adult Content Lures
BlackCat/ALPHV
Cl0p
Ryuk
Black Basta
Bulletproof Hosting
LLMNR Poisoning
SMB Relay
DLL Injection
Digital Signature Evasion
Credential Access
Password Guessing
DGA-based C&C
Remote Management Software Abuse

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.