Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SMOKY SPIDER

Description

Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.

AI Analysis

· 1 week ago

Executive Summary

SMOKY SPIDER, operating SmokeLoader, targets financial sectors and retail through phishing campaigns, deploying malware for credential theft and financial gain.

Goals & Targeting

SMOKY SPIDER's goals seem to be financial gain, targeting sectors with high transactional data. Their victims typically include financial institutions and retail businesses, where compromised credentials can lead to significant losses.

Enhanced Description

SMOKY SPIDER is a threat actor associated with the SmokeLoader malware, noted in CrowdStrike's 2020 report. They likely distribute additional payloads such as ransomware or infostealers using their primary tool. Their targeting focus suggests intent on stealing sensitive data for financial or competitive advantage.

Key Capabilities

  • SmokeLoader malware
  • Distribution of ransomware

MITRE ATT&CK Tactics

Credential Access
Email Compromise

ATT&CK Techniques

T1056
T1058

Software / Tooling

SmokeLoader
Phishing Tools

Campaigns & Victims

Campaigns involve targeted phishing and malware deployment, focusing on sectors with financial value. No specific campaigns known beyond their association with SmokeLoader.

IOC Patterns

  • Spear-phishing emails with malicious links
  • C2 infrastructure signs like HTTP traffic anomalies

Recommended Actions

  • Enhance email filtering
  • Implement MFA for sensitive accounts
  • Monitor network activity for unknown executables

Suggested Tags

Malware
Financial Fraud
Retail Sector

Confidence Assessment

Low confidence due to limited data; gaps include exact motivations and detailed TTPs.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Malware
Financial Fraud
Retail Sector

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.