LokiBot is commodity information-stealing malware first reported in 2015, primarily associated with credential theft from Windows systems. It harvests usernames and passwords from Windows credential stores, web browsers, email clients, and FTP and SFTP clients. Supported browsers include Safari and Chromium- and Mozilla Firefox-based browsers. Its capabilities include keylogging, collection of browsing information, host reconnaissance, and backdoor access that allows attackers to install additional payloads. It communicates over HTTP and can exfiltrate stolen information through its command-and-control channel.
LokiBot is commonly distributed through phishing and spearphishing emails containing malicious documents, archives, or ISO disk images. Campaigns have used invoice, purchase-order, health-department, and COVID-19 lures. Malicious Office and RTF documents have exploited CVE-2017-11882 to download and execute it, while other infection chains have used document macros and multistage scripts. GuLoader is also known to deliver LokiBot. Observed evasion techniques include software packing, encoded strings, debugger detection, virtual-machine timing checks, hidden artifacts, and process hollowing. The malware can enumerate host identity and operating-system information and check for servers and remote-access technologies on compromised systems.
LokiBot has been used by diverse operators, including Nigerian cybercriminals tracked as SilverTerrier, Sweed, and TA558. Its deployment spans untargeted malspam and campaigns affecting government, healthcare, manufacturing, and industrial organizations. Android banking malware has also been reported under the LokiBot name, including variants capable of switching to ransomware behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
February 2018: Trend Micro discovered CVE-2017-11882 being exploited in an attack using Windows Installer service to deliver LokiBot malware.
The malicious document is a xlsx file that contains a blurred image... The document tries to exploit a vulnerability found in Microsoft Office and WordPad, that is described in CVE-2017-0199. If successful, the malware would download a file found at http[:]//itssotiny.com/fYYbO. | The purpose of this campaign is to deploy the Lokibot stealer on the infected machines.
In a recent FortiGuard Labs investigation, we came across several malicious Microsoft Office documents designed to exploit known vulnerabilities. Specifically, CVE-2021-40444 and CVE-2022-30190 are remote code execution vulnerabilities. | LokiBot, also known as Loki PWS, has been a well-known information-stealing Trojan active since 2015. It primarily targets Windows systems and aims to gather sensitive information from infected machines.
Specifically, CVE-2021-40444 and CVE-2022-30190 are remote code execution vulnerabilities. Exploiting these vulnerabilities allowed the attackers to embed malicious macros within Microsoft documents that, when executed, dropped the LokiBot malware onto the victim's system. | LokiBot, also known as Loki PWS, has been a well-known information-stealing Trojan active since 2015. It primarily targets Windows systems and aims to gather sensitive information from infected machines.
The malicious web page exploits a vulnerability identified as CVE-2016-0189 to run the embedded PowerShell script. | We recently detected an aggressive malware distribution campaign delivering LokiBot via multiple techniques, including the exploitation of older vulnerabilities.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Attached to the email was a sample of Lokibot malware disguised as an Indonesian health department document.”
“Attached to the email was a sample of Lokibot malware disguised as an Indonesian health department document.”
LokiBot is a stealer that collects data from various applications used by the victim, such as browsers, email and FTP clients.
常用的攻击工具包括疑似自主开发的office文档公式编辑器漏洞利用工具、恶意office宏制作工具、AgentTesla木马、Formbook木马、Lokibot木马。
An email campaign attempting to distribute the Lokibot password-stealing malware used a message attempting to spoof company emails on COVID-19 response policy as a lure.
The group relied exclusively on a variety of publicly available spyware and Remote Access Trojans (RATs), including AgentTesla, Lokibot, AzoRult, Pony, and NetWire.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
LokiBot has used process hollowing to inject into legitimate Windows process vbc.exe.
LokiBot has the ability to capture input on the compromised host via keylogging.
LokiBot has the ability to discover the domain name of the infected host.
LokiBot has the ability to discover the username on the infected host.
2,949 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
182 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as the original ancestor of the separate lineage leading to BlackRock. Its author reportedly released the source publicly after an unsuccessful sale; the article does not describe its capabilities.
An infostealer that steals credentials from browsers, FTP clients, and other applications, exfiltrates them to C2 via compressed POST requests, and can receive commands to download additional malware or run a keylogger.
Commodity credential-stealing malware used in COVID-themed phishing campaigns.
LokiBot is discussed as malware using C2 infrastructure; the article traces infrastructure pivots starting from a domain identified as a LokiBot C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.