Files
cert-orangecyberdefense-cti/smartloader
CERT Orange Cyberdefense 60cf82992f history typo
2025-03-13 17:04:13 +01:00
..
2025-03-12 11:26:22 +01:00
2025-03-13 17:04:13 +01:00

Following a recent TrendMicro investigation, we have found many GitHub repositories actively delivering SmartLoader. SmartLoader is Lua-written loader distributed since mid 2023.

In recent campaigns, threat actors have been creating new GitHub repositories populated with an AI generated README and filled with fake backdated commits. We have also observed the same payloads being distributed via inactive repositories. These repositories are typically forked, with a new release containing SmartLoader ultimately added.

We have uploaded on our GitHub an additional list of IoCs that complements TrendMicro's report.

Released on 2025-03-12