Also known as: tracked as, APT28, Pawn Storm, Fancy Bear, AMOS, BlackCat, fields, Sednit, Zeus
Malsmoke first surfaced in late 2019 and has evolved from traditional exploit‑kit operations—using Fallout—to sophisticated social engineering via fake Java updates and adult content lures. The actor delivers Zloader through high‑traffic malvertising campaigns, then escalates to ransomware deployment (Zloader, BlackCat/ALPHV, Cl0p, Ryuk) by leveraging shared bulletproof hosting and DGA‑generated C2 domains. Operationally, Malsmoke employs a hybrid toolset that combines commercial frameworks such as Cobalt Strike and Mythic with open‑source exploit tools like Metasploit, Havoc, and Sliver. Initial access is often achieved through legitimate remote management software (Atera) or SSH tunneling, followed by credential‑guessing attacks, LLMNR/NBT-NS poisoning, and SMB relay for lateral movement. Persistence tactics include DLL injections into digitally signed system libraries, regsvr32-based execution of custom DLLs, mshta.exe usage, and startup‑folder scripts. Defense evasion is achieved via obfuscated payloads (T1027), encrypted files, PowerShell scripting, and exploitation of Microsoft’s digital signature verification. Financial gain remains the primary motivation, as evidenced by recurring ransomware extortion attempts that encrypt victim data for ransom payments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Malsmoke is a financially motivated threat actor that targets predominantly Japanese users through malvertising on adult sites, delivering malware such as Zloader and later ransomware payloads. The group shares infrastructure with several ransomware affiliates, uses a mix of commercial and open-source post‑exploitation frameworks, and frequently leverages legitimate remote management software for initial access. Its campaigns combine advanced lateral movement techniques, DLL injection into signed libraries, and DGA-based C2 domains to evade detection while maintaining a rapid operational tempo.
Goals & Targeting
Malsmoke’s strategic objective centers on maximizing financial returns through ransomware extortion while masking its footprints via shared infrastructure. It selectively targets sectors with high-value data—financial services, defense contractors, manufacturing firms, and nonprofits—focusing on Japanese organizations but also extending operations to the US, Canada, and China. By leveraging broad geographic IPs in ad networks and low‑cost hosting, the actor can maintain a high operation volume with reduced attribution risk.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Malsmoke operates with a rapid, opportunistic cadence, frequently launching new batches of adult‑content malvertising over several days and quickly pivoting to ransomware deployment once footholds are established. The actor shows a preference for high‑traffic but low‑security environments (adult sites in Japan) that allow wide distribution of its payloads while staying under the radar. Infrastructure reuse—with shared bulletproof hosting IPs and DGA domains—indicates deliberate collusion or outsourcing with other ransomware affiliates to dilute attribution. Victims are predominantly small‑to‑medium enterprises in finance, defense, nonprofit, and manufacturing sectors; however, any organization exposed on the actor’s malicious ad networks remains at risk.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The compiled intelligence comes from multiple fragmented sources, providing a consistent picture of Malsmoke’s tactics, techniques and procedures but leaving notable gaps. While financial motive is strongly implied through ransomware activity, the actor’s exact operational timeline, attribution to specific geopolitical objectives, and comprehensive malware taxonomy remain uncertain. Further analysis of host footprints and code samples would increase confidence in the identified capabilities and tool associations.
No campaigns linked yet.
No observed data linked yet.
25
Techniques
49
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics