Malware
SMOKEDHAM
According to Mandiant, SMOKEDHAM is dropped through a powershell script that contains the (C#) source code for this backdoor, which is stored in an encrypted variable.
SMOKEDHAM is a Windows malware family.
Background
Mandiant reports that SMOKEDHAM is delivered via a PowerShell script holding the backdoor's (C#) source code inside an encrypted variable. The dropper defines a cmdlet and .NET class for the backdoor on the fly, so the compiled code exists only in memory.
Source: Malpedia (Fraunhofer FKIE).