Uptime Hamster: 10d 20h 51mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza SMOKY SPIDER

SMOKY SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
SMOKY SPIDER is a financially motivated cybercrime group that emerged in 2011, primarily known for developing and operating Smoke Loader, a modular malware downloader and distribution service. The group is assessed with high confidence to be of Russian origin, focusing on data exfiltration and ransomware deployment. Their unique characteristic lies in pioneering the use of their proprietary Smoke Loader malware as a flexible platform for delivering various secondary payloads, establishing it as a significant component in the cybercrime ecosystem for initial access and distribution. This group has increasingly adopted double extortion tactics in their ransomware operations.

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Malware asociado
SMOKELOADER, Smoke Loader, Smoke Loader, win.smokeloader
Tecnicas MITRE
T1078.003, T1567.002, T1021.001, T1203
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
17
Actualizado
Mon, 13 Ap

Sectores objetivo (SOCRadar)

Information ServicesFinanceHealthCare & Social AssistanceAir TransportationSpace & DefenseRetail