Skip to content

Malware

SMOKEDHAM

According to Mandiant, SMOKEDHAM is dropped through a powershell script that contains the (C#) source code for this backdoor, which is stored in an encrypted variable.

SMOKEDHAM is a Windows malware family.

Background

Mandiant reports that SMOKEDHAM is delivered via a PowerShell script holding the backdoor's (C#) source code inside an encrypted variable. The dropper defines a cmdlet and .NET class for the backdoor on the fly, so the compiled code exists only in memory.


Source: Malpedia (Fraunhofer FKIE).