Lokibot

MITRE ATT&CK: S0447 View on attack.mitre.org

Aliases: Lokibot

First seen
2015-01-01 00:00:00
Malware type
credential-stealer, backdoor
Family
Malware family
Operating systems
windows
Related IoCs
5306 (3994 malicious)
Last IoC activity
2026-09-02 02:41:20
Profile updated
2026-07-07 14:08:10

Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications

Context

Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads.

Recent IoC activity

3,994 malicious indicators in Maltiverse are attributed to Lokibot (S0447). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname sariincofood.co.id 2026-09-03 2
IP address 158.94.211.95 2026-09-03 4
URL http://158.94.211.95/kelly/five/ 2026-09-03 1
URL https://contirecovery.best 2026-09-03 1
hostname abscete.info 2026-09-03 3
hostname gamestoredownload.download 2026-09-03 4
hostname es02.xyz 2026-09-03 3
hostname pkhz.xyz 2026-09-03 2
hostname mxrz.xyz 2026-09-03 3
hostname isolve-id.com 2026-09-03 3
hostname ciuj.ir 2026-09-03 4
hostname purinex.co.id 2026-09-03 3
hostname erobinhood.com 2026-09-03 2
hostname ecoorganic.co 2026-09-03 3
URL http://abscete.info/hero/five/PvqDq929BSx_A_D_M1n_a.php 2026-09-02 1
URL http://jvl-jp.co/saka/PvqDq929BSx_A_D_M1n_a.php 2026-09-02 1
URL http://www.gtrnusa.com/bazziniltd/benson/PvqDq929BSx_A_D_M1n_a.php 2026-09-02 1
URL http://alifmedical.shop/vbnm/Panel/PvqDq929BSx_A_D_M1n_a.php 2026-09-02 2
URL http://sahakyanshn.com/boss/five/PvqDq929BSx_A_D_M1n_a.php 2026-09-02 1
URL http://efore.info/123/five/PvqDq929BSx_A_D_M1n_a.php 2026-09-02 1

Detection coverage

  • 801 Sigma rules

Malware & tools used

  • Spearphishing Attachment (attack-pattern)
  • Software Packing (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Process Hollowing (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Modify Registry (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Time Based Checks (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Scheduled Task/Job (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • PowerShell (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Malicious File (attack-pattern)
  • Web Protocols (attack-pattern)

Used by threat actors

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Lokibot (report)
  • embee-research.ghost.io — Infrastructure Analysis With Dns Pivoting (report)
  • news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
  • ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
  • isc.sans.edu — 27282 (report)
  • drive.google.com — View (report)
  • github.com — Machete%20Weapons Lokibot En (report)
  • threatfabric.com — Lokibot The First Hybrid Android Malware (report)
  • Kaspersky — 110286 (report)
  • yoroi.company — Aggah How To Run A Botnet Without Renting A Server For More Than A Year (report)
  • muha2xmad.github.io — Lokibotpdf (report)
  • Cisco Talos — A Deep Dive Into Lokibot Infection Chain (report)
  • MITRE ATT&CK — S0447 (report)
  • blog.morphisec.com — Lokibot With Autoit Obfuscator Frenchy Shellcode (report)
  • insights.infoblox.com — Threat Intelligence 22 (report)
  • CISA — Aa20 266A (report)

External references