Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
Executive Summary
SMOKY SPIDER, operating SmokeLoader, targets financial sectors and retail through phishing campaigns, deploying malware for credential theft and financial gain.
Goals & Targeting
SMOKY SPIDER's goals seem to be financial gain, targeting sectors with high transactional data. Their victims typically include financial institutions and retail businesses, where compromised credentials can lead to significant losses.
Enhanced Description
SMOKY SPIDER is a threat actor associated with the SmokeLoader malware, noted in CrowdStrike's 2020 report. They likely distribute additional payloads such as ransomware or infostealers using their primary tool. Their targeting focus suggests intent on stealing sensitive data for financial or competitive advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns involve targeted phishing and malware deployment, focusing on sectors with financial value. No specific campaigns known beyond their association with SmokeLoader.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited data; gaps include exact motivations and detailed TTPs.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics