L0rdix
Aliases: lordix
- First seen
- 2018-11-01 00:00:00
- Malware type
- rat, credential-stealer, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 15:10:07
Context
L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018. Out of the box, L0rdix supports eight commands, although custom commands can be defined and added. These include: Download and execute Update Open page (visible) Open page (invisible) Cmd Kill process Upload file HTTP Flood L0rdix can extract credentials from common web browsers and steal data from crypto wallets and a target's clipboard. Optionally, L0rdix can deploy a cryptominer (XMRig) to its bots.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Lordix (report)
- twitter.com — 1058356670835908610 (report)
- github.com — Decrypt L0Rdix C2.Py (report)
- bromium.com — Decrypting L0Rdix Rats C2 (report)
- blog.ensilo.com — L0Rdix Attack Tool (report)
- bromium.com — An Analysis Of L0Rdix Rat Panel And Builder (report)