Smoke and Fire – Smokeloader Historical Changes and Trends
Marcos Alvares 🗣
Smokeloader (aka Sharik or SmokeBot) turned 10 in 2021! Few malware families make to this mark without collapsing or getting caught by law enforcement. For over a decade, Smokeloader has been deployed as part of distribution schemes of many high-profile financially motivated malware families, such as Dridex, Trickbot, ISFB and SilentNight. Its simplicity and business model have contributed to this longevity. This presentation intends to provide (i) a technical overview on key changes implemented over the past 10 years, (ii) statistics on customers and infrastructure and (iii) highlights on tactics that helped smokeloader survive all this time.