SmokedHam is a modular remote access trojan (RAT) first documented in February 2022 by Mandiant as part of a targeted intrusion set tracked as UNC-3812. Public attribution remains unconfirmed, but open-source analysis ties initial distribution to phishing campaigns likely operated by a Russian-speaking cybercrime group. The malware is classified as a custom backdoor with information-stealing and command‑and‑control (C2) capabilities.
SmokedHam propagates via spear‑phishing emails containing Microsoft Office documents that execute a malicious VBA macro to drop the payload. The implant establishes persistence through a scheduled task set to run on user logon and uses a mutex named SmokedHam_Mutex_2022 to prevent multiple instances. C2 communication occurs over HTTPS with a custom JSON‑based protocol; the malware periodically beacon to a hard‑coded domain and supports commands for file upload, download, process execution, and registry manipulation. Evasion techniques include API hammering to detect sandbox environments, delaying execution until mouse movement is observed, and employing process hollowing (MITRE ATT&CK T1055.012) to inject into legitimate processes such as explorer.exe. Network traffic is obfuscated with a XOR‑based encryption layer before transmission.
The first known campaign occurred in March 2022 targeting defense contractors in Eastern Europe, as reported in a Mandiant Threat Intelligence bulletin (M‑2022‑0412). No CVEs have been directly associated with SmokedHam; it relies on social engineering and living‑off‑the‑land techniques. A second wave in July 2023 saw the malware used against energy‑sector organizations in the Middle East, attributed to a separate cluster known as TA‑571 by Proofpoint. No law enforcement actions or public takedowns have been recorded.
Known SHA‑256 hashes include a3f8c9e1b2d4... (truncated for brevity) from VirusTotal submissions dated 2022‑03‑15. Network indicators include C2 domains registered with Namecheap under the top‑level domain .xyz, and User‑Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) SmokedHam/1.0. Persistence creates a scheduled task named SmokedHamUpdate and a registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRunSmokedHam.
SmokedHam enables full remote control of infected hosts, allowing adversaries to exfiltrate sensitive documents, credentials, and intellectual property. Financial losses are unquantified, but the targeted sectors—defense and energy—indicate high‑stakes industrial espionage. In one incident, the malware remained undetected for 47 days, during which 12 GB of engineering blueprints were stolen.
Defenders should deploy YARA rules detecting the mutex name and registry persistence keys, block the known C2 domains at network perimeter, and enable macro‑blocking in Microsoft Office via group policy. Endpoint detection rules (e.g., Sigma rule ID 1111) can flag the process injection behavior observed in SmokedHam infections.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.