Threat Profile: Dofoil (Smoke Loader) Trojan with Coin-Miner

smokeloader trojan

 

These days, most malware employs a long attack chain with anti-analysis techniques to make it more difficult to detect the payload and harder to analyze by security researchers. More and more frequently, they are also incorporating coin miners in attacks. Such is the case with a newly observed variant of the Dofoil (also known as Smoke Loader) trojan, which includes a resource-draining cryptocurrency-mining payload. This latest Dofoil strain entered the scene earlier this month and is currently still active.

Article Link: http://blog.morphisec.com/dofoil-trojan-coin-miner