Skip to main content
Skip to main content
6 entries found.
Updated on Nov 29, 2011
Alert level: severe
Updated on Nov 24, 2011

DDoS:Win32/Dofoil.A is a trojan that connects to a remote website to download and execute arbitrary files. It may also receive instructions from the remote server to perform distributed denial-of-service (DDoS) attacks against certain websites.

On March 6, 2018, behavior monitoring and machine learning technologies in Microsoft Defender Antivirus stopped a Dofoil variant (also known as Smoke Loader) that tried to infect more than 400,000 computers. The massive campaign aimed to install a cryptocurrency miner that uses victim computers' resources for coin mining purposes. Learn how artificial intelligence stopped the attack within minutes:

Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign

Alert level: severe
Updated on Aug 08, 2012
Alert level: severe
Updated on Oct 17, 2025
Alert level: severe
Updated on Dec 26, 2021
Alert level: severe
Updated on Feb 24, 2017
Alert level: severe