LodaRAT, also known as Loda, is a remote access trojan active since at least 2016 and used for information theft and cyberespionage. Its Windows implementation is written in AutoIt; a related Android variant is known as Loda4Android and was previously identified as Gaza007 RAT. Development has been linked to the group tracked as Kasablanka, also called Kasablanca, but the malware is used by multiple independent operators, including YoroTrooper and TA558. Campaigns have targeted Bangladesh-based banks and carrier-grade voice-over-IP software vendors, while other deployments have reached government, energy, and additional organizations internationally.
Windows variants support operator-issued commands, screenshot capture, keylogging, microphone and webcam recording, and theft of browser passwords and cookies, including from Microsoft Edge and Brave. Persistence mechanisms include startup execution, registry modifications, and scheduled tasks. Some variants can enable RDP access, create local accounts, disable Windows Firewall, and spread to other systems over SMB. Command-and-control communications have also used legitimate tunneling and port-forwarding services. Functionality varies between builds, and embedded version numbers do not reliably establish their lineage.
Distribution includes phishing emails carrying malicious Office documents or compressed executable attachments, as well as deceptive websites impersonating government services and other legitimate organizations. Document-based infection chains have exploited CVE-2017-0199 and CVE-2017-11882; some abuse legitimate Windows utilities to execute downloaded scripts and bypass application controls. Other campaigns rely on victims manually launching disguised executables.
Loda4Android provides remote command and script execution, location tracking, ambient audio recording, photograph and screenshot capture, and exfiltration of stored SMS messages, call logs, and contacts. It can send SMS messages, place calls, launch applications, and present a built-in Facebook phishing interface. Its telephone recording capability captures only the infected user's side of a conversation rather than intercepting calls.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Adversaries use a malicious RTF document that exploits CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office — that, in turn, downloads a malicious SCT file.
In most of its campaigns, LodaRAT has been spreading through malicious documents, that either contained malicious macros or exploited vulnerabilities in Office. Some earlier campaigns exploited CVE-2017-0199, while more recent ones exploited CVE-2017-11882. | LodaRAT, or Loda, is information gathering malware. It has the ability to take screenshots of infected machines, record keystrokes and sound and allows its operators to send commands to the machine.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Windows-based samples identified during this investigation are updated versions of LodaRAT. While mostly remaining the same as previously discovered versions, new commands have been added that extend its capabilities and utilize a slightly different infection chain.
Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
LodaRAT, or Loda, is information gathering malware. It has the ability to take screenshots of infected machines, record keystrokes and sound and allows its operators to send commands to the machine.
YoroTrooper has relied heavily on the use of primarily two commodity malware families, AveMaria/Warzone RAT and LodaRAT, especially in October and November 2022.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Loda is now being distributed via a malicious RAR archive attached to phishing emails.
LodaRAT ... allows its operators to send commands to the machine.
In one version, a hex-encoded PowerShell keylogger script has been added... If the command "MgPlugUp" is received from C2, the script is written to a file called "tmpwstz21.ps1" and executed.
A VB script has also been added that searches for the Loda AutoIt script by process name to ensure only one instance is running.
The malicious SCT file is essentially an XML file that contains JavaScript that downloads and executes the Loda binary.
In previous campaigns, the infection chain started with a malicious Microsoft Word document that downloaded a second document which then exploited CVE-2017-11882.
The RAR attachments have the file extension ".rev"... However, the files attached to these emails were standard RAR files with the extension name changed.
In one version, a hex-encoded PowerShell keylogger script has been added... The logs are output into the temp directory as a text file named with the current date.
LodaRAT ... has the ability to take screenshots of infected machines, record keystrokes and sound ...
For both versions, C2 communication has shifted to abusing legitimate services. Ngrok.io and portmap.io were both observed to be used during analysis.
For both versions, C2 communication has shifted to abusing legitimate services. Ngrok.io and portmap.io were both observed to be used during analysis.
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan listed as one of the malware families deployed by TA558 for remote control and information theft.
LodaRAT is a remote access trojan active since 2016, used for information gathering, cyber-espionage, and data theft. The latest variant targets browser credentials, captures screens, records audio/video, creates user accounts, disables firewalls, and spreads laterally via SMB. It is distributed via phishing, vulnerability exploitation, and loaders like DonutLoader and CobaltStrike.
RAT family used by YoroTrooper; Talos notes LodaRAT is attributed to (and likely developed by) the Kasablanka actor but appears used by multiple distinct operators/campaigns. YoroTrooper’s LodaRAT variants deviate from versions previously associated with Kasablanka and resemble versions seen in crimeware campaigns alongside RedLine and VenomRAT.
Information-gathering malware / RAT used in campaigns targeting Bangladesh. It can capture screenshots, log keystrokes, record audio, and execute operator commands on infected systems. The campaign delivered Windows variants via fake Bangladesh-themed websites and malicious ZIP archives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.