APTMembers
APT

SmokeLoader Campaign Adds Trojanized Card-Checker Lure, Third C2 Node

A SmokeLoader-driven infostealer operation targeting Spain has expanded its kill chain with a trojanized credit-card-checker utility as a second initial-access vector. Seven new file indicators and a full C2 IP refresh confirm stolen Exodus wallet seeds, FileZilla credentials, and Telegram sessions are being sold through the '@MERCEDESLOGS' log marketplace. A third command-and-control IP on a structurally distinct autonomous system introduces the campaign's first domain-linked TLS endpoint.

May 30, 2026, 00:33 (UTC+9)Last seenMay 30, 2026Severity100ByCTX TeamActorAPT39ChaferIOC43MITRE48RegionsES

Since CTX Team's earlier coverage of this SmokeLoader-driven infostealer operation, seven new file indicators have surfaced alongside a full refresh of the campaign's three command-and-control IPs — and the most significant development is not the infrastructure update but what it reveals about how the operator is now getting onto victim machines.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence