Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal
Trend AI Research Blog May 2025

Agenda Ransomware Group Adds SmokeLoader and NETXLOADER to Their Arsenal

RansomwareDefense EvasionCross-Platform

During monitoring of Agenda (Qilin) ransomware activities, campaigns were uncovered using the SmokeLoader malware and a newly identified loader named NETXLOADER. The addition of these tools to Agenda's arsenal demonstrates the group's continued evolution in delivery mechanisms and evasion capabilities. NETXLOADER features .NET-based obfuscation and dynamic payload retrieval, while SmokeLoader provides modular post-exploitation capabilities. The research documents the full kill chain from initial access through loader deployment to ransomware execution.