Loda
Aliases: LodaRAT, Nymeria
- First seen
- 2016-09-01 00:00:00
- Malware type
- spyware, rat, keylogger
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 13:06:30
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims. Proofpoint first observed Loda in September of 2016 and it has since grown in popularity. The name Loda is derived from a directory to which the malware author chose to write keylogger logs. It should be noted that some antivirus products currently detect Loda as “Trojan.Nymeria”, although the connection is not well-documented.
Reports & references
- Cisco Talos — Yorotrooper Espionage Campaign Cis Turkey Europe (report)
- Cisco Talos — Get A Loda This (report)
- Cisco Talos — Attributing Yorotrooper (report)
- mp.weixin.qq.com — Mstwbmks0G3Et4Goji2Mwa (report)
- proofpoint.com — Reservations Requested Ta558 Targets Hospitality And Travel (report)
- ti.qianxin.com — Kasablanka Group Probably Conducted Compaigns Targeting Russia (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Loda (report)
- Cisco Talos — Kasablanka Lodarat (report)
- proofpoint.com — Introducing Loda Malware (report)
- silentpush.com — More Lodarat Infrastructure Targeting Bangladesh Uncovered (report)
- zerophagemalware.com — Maldoc Rtf Drop Loda Logger (report)
- Cisco Talos — Loda Rat Grows Up (report)
- Cisco Talos — Lodarat Update Alive And Well (report)