The group blends into an environment before loading up trivial, thickly stacked, fraudulent financial transactions too tiny to be noticed but adding up to millions of dollars.
https://threatpost.com/elephant-beetle-months-networks-financial/177393/
Some security researchers say it’s actually Cobalt Strike and not a SmokeLoader variant, but BioBright says in-depth testing shows it’s for real a scary morphic malware that changes its parts and recompiles itself.
https://threatpost.com/shape-shifting-tardigrade-malware-hits-vaccine-makers/176601/