Lokibot
MITRE ATT&CK: S0447 View on attack.mitre.org
Aliases: Lokibot
- First seen
- 2015-01-01 00:00:00
- Malware type
- credential-stealer, backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 5306 (3994 malicious)
- Last IoC activity
- 2026-09-02 02:41:20
- Profile updated
- 2026-07-07 14:08:10
Targeted industries: financial-services retail-and-hospitality technology-and-telecommunications
Context
Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads.
Recent IoC activity
3,994 malicious indicators in Maltiverse are attributed to Lokibot (S0447). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | sariincofood.co.id | 2026-09-03 | 2 |
| IP address | 158.94.211.95 | 2026-09-03 | 4 |
| URL | http://158.94.211.95/kelly/five/ | 2026-09-03 | 1 |
| URL | https://contirecovery.best | 2026-09-03 | 1 |
| hostname | abscete.info | 2026-09-03 | 3 |
| hostname | gamestoredownload.download | 2026-09-03 | 4 |
| hostname | es02.xyz | 2026-09-03 | 3 |
| hostname | pkhz.xyz | 2026-09-03 | 2 |
| hostname | mxrz.xyz | 2026-09-03 | 3 |
| hostname | isolve-id.com | 2026-09-03 | 3 |
| hostname | ciuj.ir | 2026-09-03 | 4 |
| hostname | purinex.co.id | 2026-09-03 | 3 |
| hostname | erobinhood.com | 2026-09-03 | 2 |
| hostname | ecoorganic.co | 2026-09-03 | 3 |
| URL | http://abscete.info/hero/five/PvqDq929BSx_A_D_M1n_a.php | 2026-09-02 | 1 |
| URL | http://jvl-jp.co/saka/PvqDq929BSx_A_D_M1n_a.php | 2026-09-02 | 1 |
| URL | http://www.gtrnusa.com/bazziniltd/benson/PvqDq929BSx_A_D_M1n_a.php | 2026-09-02 | 1 |
| URL | http://alifmedical.shop/vbnm/Panel/PvqDq929BSx_A_D_M1n_a.php | 2026-09-02 | 2 |
| URL | http://sahakyanshn.com/boss/five/PvqDq929BSx_A_D_M1n_a.php | 2026-09-02 | 1 |
| URL | http://efore.info/123/five/PvqDq929BSx_A_D_M1n_a.php | 2026-09-02 | 1 |
Detection coverage
- 801 Sigma rules
Malware & tools used
- Spearphishing Attachment (attack-pattern)
- Software Packing (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Process Hollowing (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Windows Command Shell (attack-pattern)
- Modify Registry (attack-pattern)
- Scheduled Task (attack-pattern)
- Time Based Checks (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Scheduled Task/Job (attack-pattern)
- Bypass User Account Control (attack-pattern)
- System Information Discovery (attack-pattern)
- Native API (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- PowerShell (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Malicious File (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- TA2536 (threat-actor)
- SilverTerrier (threat-actor)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Lokibot (report)
- embee-research.ghost.io — Infrastructure Analysis With Dns Pivoting (report)
- news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
- ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
- isc.sans.edu — 27282 (report)
- drive.google.com — View (report)
- github.com — Machete%20Weapons Lokibot En (report)
- threatfabric.com — Lokibot The First Hybrid Android Malware (report)
- Kaspersky — 110286 (report)
- yoroi.company — Aggah How To Run A Botnet Without Renting A Server For More Than A Year (report)
- muha2xmad.github.io — Lokibotpdf (report)
- Cisco Talos — A Deep Dive Into Lokibot Infection Chain (report)
- MITRE ATT&CK — S0447 (report)
- blog.morphisec.com — Lokibot With Autoit Obfuscator Frenchy Shellcode (report)
- insights.infoblox.com — Threat Intelligence 22 (report)
- CISA — Aa20 266A (report)
External references
- mitre-attack — S0447
- Lokibot
- Infoblox Lokibot January 2019
- Morphisec Lokibot April 2020
- CISA Lokibot September 2020
- Talos Lokibot Jan 2021
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy