ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Sophisticated SmokeLoader Malware Campaign Targets Taiwanese Enterprises

Threat Actors Exploit Legacy Vulnerabilities in Precision Attack

Christi by Christi
December 2, 2024
in Malware
Reading Time: 2 mins read
SmokeLoader targets Taiwanese firms via sophisticated phishing, exploiting legacy vulnerabilities and harvesting credentials across multiple sectors with modular malware attacks.
Share on FacebookShare on Twitter

A highly sophisticated cyber campaign targets Taiwanese companies across multiple critical sectors, leveraging an advanced strain of SmokeLoader malware that goes far beyond traditional malware delivery methods. FortiGuard Labs has uncovered a meticulously crafted attack demonstrating the evolving complexity of modern cybersecurity threats.

Precision-Crafted Phishing Strategy

The campaign, active in September, employs carefully constructed phishing emails designed to deceive targets in the manufacturing, healthcare, and information technology industries.

fig01 smokeloader
Attack flow, Credits: Fortinet

These emails, written with native Chinese linguistic nuances, masquerade as seemingly legitimate price quotes—a tactic that significantly increases their potential success rate.

Multilayered Infection Mechanism

The infection process is a testament to the threat actors’ technical sophistication. Upon a recipient downloading the malicious Office document, an initial VBS file loads AndeLoader, which ultimately delivers the SmokeLoader payload.

What makes this campaign particularly insidious is its exploitation of seemingly obsolete security vulnerabilities from 2017, specifically CVE-2017-0199 and CVE-2017-11882.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Advanced Malware Capabilities

Unlike traditional malware, SmokeLoader is a modular threat with extensive capabilities. Once a system is compromised, the malware can:

  • Extract login credentials from multiple browsers including Chrome, Firefox, and Edge
  • Harvest autofill data and browser cookies
  • Collect credentials from Microsoft Outlook and FTP clients like FileZilla and WinSCP
  • Inject malicious plugins into system processes to avoid detection

Evasion and Persistence Tactics

The malware employs advanced evasion techniques that make detection challenging. By injecting plugins into suspended processes like explorer.exe and modifying their memory, the threat actors can resume execution while maintaining stealth.

Additionally, the malware establishes persistence by strategically altering registry keys, ensuring continued operation even after system reboots.

In one observed instance, researchers discovered SmokeLoader downloaded nine distinct plugins, each carefully injected into appropriate system architectures. T

The potential for data breach and corporate espionage is significant, with threat actors capable of accessing internal company information and potentially spreading the attack through compromised employee accounts.

Previous Post

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

Next Post

Vodka Giant Stoli Group Files for Bankruptcy After Devastating Ransomware Attack

Christi

Christi

Christi began her InfoSec carrier at the Illinois Institute of Technology where she received her Bachelor of Science degree in Applied Cybersecurity and Information Technology. Her passions include learning about new threats, data breaches, running, and playing with her dog, Pablo.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.