Loki is a name used for multiple unrelated malware families, most commonly a Windows information stealer and, separately, a newer Windows backdoor compatible with the Mythic and Havoc post-exploitation ecosystems. The Windows infostealer variant is widely associated with credential theft and data exfiltration, including theft of credentials from web browsers and FTP clients, cryptocurrency wallet data, and other user information. It has been delivered through several email-borne infection chains, including malicious RTF documents exploiting CVE-2017-11882, HTA and script-based downloaders, and compressed archive attachments such as CAB and LZH files. Observed execution chains include PowerShell downloaders, VBS stages, steganographic payload concealment, process hollowing, and injection into legitimate Windows processes for defense evasion and execution.
Loki infostealer activity has been observed in spam and spearphishing campaigns targeting enterprises across sectors including energy, oil and gas, electronics, manufacturing, and media, with notable targeting of South Korean organizations. In those campaigns, attackers used business-themed lures and disk-image or archive attachments to deliver Loki alongside other commodity stealers and keyloggers. The malware has also been associated with broad criminal botnet activity and was one of the most prominent credential-stealing families seen in botnet controller telemetry in the late 2010s.
A distinct malware family also named Loki emerged in targeted attacks against Russian organizations. This Loki is a private Windows backdoor derived from an agent for the Mythic framework and adapted from Havoc tooling. It operates as a loader plus in-memory DLL architecture, profiles the host, exchanges AES-encrypted and Base64-encoded data with command-and-control infrastructure, and supports post-exploitation functions including process creation, file transfer, code injection, token-related operations, environment discovery, and execution of Beacon Object Files. Multiple versions have been documented, including Loki 2.0 and 2.1, with delivery via phishing-linked archives and decoy documents in campaigns attributed to the Arcane Werewolf or Mythic Likho cluster. This backdoor inherits anti-analysis and evasion traits from Havoc-derived code, including encrypted memory, indirect API invocation, and hashed API resolution.
The name Loki has also appeared in Android malware reporting, where it has been used for malicious adware or spyware found preinstalled on some devices in supply-chain compromise cases. Because the same name is applied to several unrelated malware families across Windows and Android ecosystems, precise identification requires campaign and behavioral context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday. | Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The cluster develops and updates its custom malware toolkit, deploying a new Loki 2.1 implant compatible with the Mythic and Havoc post-exploitation frameworks.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware were already present on the devices even before the users received them. The malicious apps were not part of the official ROM supplied by the vendor, and were added somewhere along the supply chain.
The PDF sample only contains one page, shown above, which includes some social engineering content to entice users to download and run the malware.
The Cobalt hacking group also weaponized this security flaw in one of their campaigns in late November, sending out a similarly constructed RTF file. In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike.
The payload is dropped via an HTML Application (HTA) that invokes PowerShell, which then retrieves the information stealer.
Once downloaded, this file is saved as picturewithattitudeeventforallthings.vbs under %user%\AppData\Roaming\ directory. After the VBS file was executed with wscript.exe
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI).
All the APIs being called in this malware are hidden, which will be restored before calling. This increases the difficulty for researchers to analyze it.
Steganography has been applied to the image to conceal additional Base64-encoded instructions.
When this malware is executed the very first time, it copies itself to “%AppData%\subfolder”, and renames it as “citrio.exe” in my test enviroment.
This encoded portion is then reversed, decoded, and the code is injected into the aspnet_regbrowsers.exe process
It eventually uses process hollowing to load and execute the main Loki payload.
The dropped malware is generally able to steal private information, log keyboard strokes and steal browsing data.
The author of the malware has written a number of functions for stealing credentials from a victim’s machine.
Browser software: Mozilla Firefox, IceDragon, Safari, K-Meleon, Mozilla SeaMonkey, Mozilla Flock, NETGATE Black Hawk, Lunascape, Comodo Dragon, Opera Next, QtWeb, QupZilla, Internet Explorer, Opera, 8pecxstudios, Mozilla Pale Moon, Mozilla Waterfox.
The malware steals png and rtf files from the sub-folders “\stickies\images” and “\stickies\rtf” in several system directories, such as %AppData%, %UserProfile%.
The dropped malware is generally able to steal private information, log keyboard strokes and steal browsing data.
Then the injected process further starts to communicate with C2
L’API Telegram Bot est massivement exploitée par des auteurs de malwares comme canal d’exfiltration et de commande/contrôle (C2).
125 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware family observed using Telegram as C2/exfiltration infrastructure.
Information-stealing malware used in the campaign; the article groups it with malware capable of stealing private and banking information, logging keystrokes, and stealing browsing data.
Custom malware used by Arcane Werewolf, capable of gathering system information, exfiltrating data, injecting code, uploading files, and terminating processes. The latest version (2.1) integrates with Mythic and Havoc post-exploitation frameworks, increasing its flexibility and threat level.
Custom malware used by Arcane Werewolf consisting of a loader and an implant. The loader collects host information, AES-encrypts and Base64-encodes it, exfiltrates it to C2, retrieves or decrypts an implant, and executes it. The implant supports command execution, file upload/download, process creation, code/DLL injection, BOF execution, token management, environment enumeration, directory changes, and process termination.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.