Kasablanca is the malware-development group associated with LodaRAT for Windows and Loda4Android, previously known as Gaza007 RAT. The Windows and Android malware share code characteristics, command-and-control protocol design, and infrastructure. Kasablanca's relationship to the operators deploying these tools has not been conclusively established. An associated campaign beginning in October 2020 targeted Windows and Android users at Bangladesh-based organizations, particularly banks and carrier-grade voice-over-IP software vendors. Delivery infrastructure included lookalike domains impersonating legitimate organizations. The Windows infection chain used malicious RTF documents exploiting Microsoft Office vulnerability CVE-2017-11882, followed by abuse of regsvr32 and Windows scriptlet execution to bypass AppLocker and download the LodaRAT payload. Loda4Android supports location tracking, ambient audio recording, photographs, screenshots, and exfiltration of stored SMS messages, call logs, and contacts. It can send SMS messages, place calls, enumerate and launch applications, and execute commands or scripts. It also incorporates a Facebook phishing kit. Its telephone-recording functionality captures only the infected user's side of a conversation; it does not intercept SMS messages or telephone calls. LodaRAT version 1.1.8 added functionality to enable RDP access, disable Windows Firewall, create a local account, and alter authentication settings to permit passwordless network logons. It also introduced BASS-based microphone recording with an operator-specified duration, replacing the previously time-limited recording mechanism.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Develops LodaRAT for Windows and Loda4Android, linked to a cross-platform campaign targeting banks and carrier-grade VoIP software vendors in Bangladesh that began in October 2020. Shared command-and-control infrastructure, protocol similarities, and code similarities connect the malware variants. The report primarily characterizes the activity as information gathering and espionage, with no associated ransomware or banking-trojan activity identified. It remains unclear whether the developers and campaign operators are identical. Developers are potentially based in Morocco; no state sponsorship is established.
Operator/developer group behind LodaRAT and Loda4Android, conducting hybrid Windows and Android espionage-oriented campaigns, particularly targeting organizations in Bangladesh.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.