![[Image: Smoke-Loader-botnet-2025.png]](https://blackhattool.com/wp-content/uploads/2025/07/Smoke-Loader-botnet-2025.png)
What is Smoke Loader?Smoke Loader is a malware loader (also called a dropper) primarily used to:
- Deploy secondary payloads
- Establish persistence
- Evade detection
- Polymorphic & Metamorphic Code
- Process Hollowing
- VM/Sandbox Evasion
- Supports multiple payload types (EXE, DLL, PowerShell scripts).
- On-demand module loading (Only fetches necessary components from C2).
- Encrypted C2 Communication (HTTPS, custom protocols).
- Registry Run Keys (HKCU\Software\Microsoft\Windows\CurrentVersion\Run).
- Scheduled Tasks (Mimics system updates).
- Windows Service Installation (Disguised as a legitimate service).
- Phishing Emails (Malicious attachments, fake invoices).
- Malvertising (Compromised ads leading to exploit kits).
- Drive-by Downloads (Watering hole attacks).
- Trojanized Software (Fake cracks, game mods).
- DDoS Capabilities (Can be rented out for attacks).
- Proxy Network (Infected machines act as SOCKS5 proxies).
- Credential Harvesting (Keylogging, form grabbing).