SMOKEDHAM
S0649 · Windows
SMOKEDHAM is a Powershell-based .NET backdoor that was first reported in May 2021.
it has been used by at least one ransomware-as-a-service affiliate.
ATT&CK S0649
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0