
SmokeLoader Campaign Adds Trojanized Card-Checker Lure, Third C2 Node
A SmokeLoader-driven infostealer operation targeting Spain has expanded its kill chain with a trojanized credit-card-checker utility as a second initial-access vector. Seven new file indicators and a full C2 IP refresh confirm stolen Exodus wallet seeds, FileZilla credentials, and Telegram sessions are being sold through the '@MERCEDESLOGS' log marketplace. A third command-and-control IP on a structurally distinct autonomous system introduces the campaign's first domain-linked TLS endpoint.
Since CTX Team's earlier coverage of this SmokeLoader-driven infostealer operation, seven new file indicators have surfaced alongside a full refresh of the campaign's three command-and-control IPs — and the most significant development is not the infrastructure update but what it reveals about how the operator is now getting onto victim machines.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read