Loda

Aliases: LodaRAT, Nymeria

First seen
2016-09-01 00:00:00
Malware type
spyware, rat, keylogger
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 13:06:30

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims. Proofpoint first observed Loda in September of 2016 and it has since grown in popularity. The name Loda is derived from a directory to which the malware author chose to write keylogger logs. It should be noted that some antivirus products currently detect Loda as “Trojan.Nymeria”, although the connection is not well-documented.

Reports & references

  • Cisco Talos — Yorotrooper Espionage Campaign Cis Turkey Europe (report)
  • Cisco Talos — Get A Loda This (report)
  • Cisco Talos — Attributing Yorotrooper (report)
  • mp.weixin.qq.com — Mstwbmks0G3Et4Goji2Mwa (report)
  • proofpoint.com — Reservations Requested Ta558 Targets Hospitality And Travel (report)
  • ti.qianxin.com — Kasablanka Group Probably Conducted Compaigns Targeting Russia (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Loda (report)
  • Cisco Talos — Kasablanka Lodarat (report)
  • proofpoint.com — Introducing Loda Malware (report)
  • silentpush.com — More Lodarat Infrastructure Targeting Bangladesh Uncovered (report)
  • zerophagemalware.com — Maldoc Rtf Drop Loda Logger (report)
  • Cisco Talos — Loda Rat Grows Up (report)
  • Cisco Talos — Lodarat Update Alive And Well (report)

External references