LodaRAT is a long-running remote access trojan and information-stealing malware family, active since at least 2016–2017, primarily associated with Windows and later expanded to Android through the related Loda4Android variant. The Windows malware is written in AutoIt and has been used for remote system control, surveillance, credential theft, and broader espionage-oriented collection. Documented capabilities include screenshot capture, keystroke logging, audio recording, browser password and cookie theft, command execution, and persistence. More recent reporting also attributes to some variants the ability to disable host defenses, create user accounts, enable remote desktop access, and attempt lateral movement over SMB. Android variants add mobile surveillance and collection functions such as location tracking, ambient audio recording, photo and screenshot capture, SMS, call log, and contact theft, as well as command execution and phishing functionality.
LodaRAT has been delivered through multiple infection chains over time. Observed Windows delivery methods include phishing emails carrying malicious Office documents, exploit-based chains using CVE-2017-0199 and CVE-2017-11882, compressed archives containing executable payloads, and lure websites serving password-protected archives. Campaigns have also used fake or impersonating websites themed around government, telecom, finance, political, and public-service subjects to target victims. Newer distribution has included renamed RAR archives requiring user execution, and some reporting links delivery to additional tooling such as DonutLoader and Cobalt Strike.
Operational use of LodaRAT spans both commodity cybercrime and targeted espionage. It has been deployed by TA558 in phishing campaigns affecting Latin America and other regions, used by YoroTrooper in espionage activity targeting government and energy organizations in CIS countries, and linked by Cisco Talos to a cluster it tracks as Kasablanca in campaigns targeting Bangladesh. Kasablanca-linked activity has been assessed as information-gathering focused and possibly consistent with cyber-mercenary or hacker-for-hire tradecraft, although that characterization is not conclusive. Targeting associated with LodaRAT has included hospitality, tourism, finance, government, energy, education, IT, pharmaceuticals, transportation, banks, VoIP vendors, diplomatic entities, and other organizations.
The malware’s command-and-control tradecraft has evolved over time and has included abuse of legitimate tunneling or port-forwarding services to obscure infrastructure. Multiple versions have been observed in parallel, with differing feature sets and code quality, suggesting either active development, reuse by multiple operators, or both. Despite these variations, LodaRAT remains best characterized as a versatile RAT used for remote access, surveillance, credential theft, and post-compromise collection across Windows and Android environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In most of its campaigns, LodaRAT has been spreading through malicious documents, that either contained malicious macros or exploited vulnerabilities in Office. Some earlier campaigns exploited CVE-2017-0199, while more recent ones exploited CVE-2017-11882. | LodaRAT, or Loda, is information gathering malware. It has the ability to take screenshots of infected machines, record keystrokes and sound and allows its operators to send commands to the machine.
Some earlier campaigns exploited CVE-2017-0199, while more recent ones exploited CVE-2017-11882. Though patched several years ago, the latter vulnerability remains popular among malware authors. | LodaRAT, or Loda, is information gathering malware. It has the ability to take screenshots of infected machines, record keystrokes and sound and allows its operators to send commands to the machine.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.
LodaRAT, or Loda, is information gathering malware. It has the ability to take screenshots of infected machines, record keystrokes and sound and allows its operators to send commands to the machine.
The developers of LodaRAT have added Android as a targeted platform. A new iteration of LodaRAT for Windows has been identified with improved sound recording capabilities.
YoroTrooper has relied heavily on the use of primarily two commodity malware families, AveMaria/Warzone RAT and LodaRAT, especially in October and November 2022.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Loda is now being distributed via a malicious RAR archive attached to phishing emails.
LodaRAT ... allows its operators to send commands to the machine.
In one version, a hex-encoded PowerShell keylogger script has been added... If the command "MgPlugUp" is received from C2, the script is written to a file called "tmpwstz21.ps1" and executed.
A VB script has also been added that searches for the Loda AutoIt script by process name to ensure only one instance is running.
The malicious SCT file is essentially an XML file that contains JavaScript that downloads and executes the Loda binary.
In previous campaigns, the infection chain started with a malicious Microsoft Word document that downloaded a second document which then exploited CVE-2017-11882.
The RAR attachments have the file extension ".rev"... However, the files attached to these emails were standard RAR files with the extension name changed.
In one version, a hex-encoded PowerShell keylogger script has been added... The logs are output into the temp directory as a text file named with the current date.
LodaRAT ... has the ability to take screenshots of infected machines, record keystrokes and sound ...
For both versions, C2 communication has shifted to abusing legitimate services. Ngrok.io and portmap.io were both observed to be used during analysis.
For both versions, C2 communication has shifted to abusing legitimate services. Ngrok.io and portmap.io were both observed to be used during analysis.
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan listed as one of the malware families deployed by TA558 for remote control and information theft.
LodaRAT is a remote access trojan active since 2016, used for information gathering, cyber-espionage, and data theft. The latest variant targets browser credentials, captures screens, records audio/video, creates user accounts, disables firewalls, and spreads laterally via SMB. It is distributed via phishing, vulnerability exploitation, and loaders like DonutLoader and CobaltStrike.
RAT family used by YoroTrooper; Talos notes LodaRAT is attributed to (and likely developed by) the Kasablanka actor but appears used by multiple distinct operators/campaigns. YoroTrooper’s LodaRAT variants deviate from versions previously associated with Kasablanka and resemble versions seen in crimeware campaigns alongside RedLine and VenomRAT.
Information-gathering malware / RAT used in campaigns targeting Bangladesh. It can capture screenshots, log keystrokes, record audio, and execute operator commands on infected systems. The campaign delivered Windows variants via fake Bangladesh-themed websites and malicious ZIP archives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.