LOBSHOT

Malware type
trojan, credential-stealer
Family
Malware family
Profile updated
2026-07-07 15:09:53

Targeted industries: financial-services

Context

According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to access a victim's computer without being noticed. The hVNC component is effective in evading fraud detection systems. Also, LOBSHOT is being used to carry out financial crimes through the use of banking trojan and information-stealing functionalities.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Lobshot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Lobshot (report)
  • research.openanalysis.net — Lobshot (report)
  • elastic.co — Elastic Security Labs Discovers Lobshot Malware (report)

External references