L0rdix

Aliases: lordix

First seen
2018-11-01 00:00:00
Malware type
rat, credential-stealer, cryptominer
Family
Malware family
Profile updated
2026-07-07 15:10:07

Context

L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018. Out of the box, L0rdix supports eight commands, although custom commands can be defined and added. These include: Download and execute Update Open page (visible) Open page (invisible) Cmd Kill process Upload file HTTP Flood L0rdix can extract credentials from common web browsers and steal data from crypto wallets and a target's clipboard. Optionally, L0rdix can deploy a cryptominer (XMRig) to its bots.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Lordix (report)
  • twitter.com — 1058356670835908610 (report)
  • github.com — Decrypt L0Rdix C2.Py (report)
  • bromium.com — Decrypting L0Rdix Rats C2 (report)
  • blog.ensilo.com — L0Rdix Attack Tool (report)
  • bromium.com — An Analysis Of L0Rdix Rat Panel And Builder (report)

External references