Trojan

Crypto Stealer

Keylogging

Credential Stealer

Lokibot

Lokibot

LokiBot—also known as Loki PWS and Loki-bot—is a Trojan malware designed to steal sensitive information, including usernames, passwords, and cryptocurrency wallet credentials. This malware operates by employing a keylogger to monitor browser and desktop activity. Additionally, LokiBot creates a backdoor into infected systems, enabling attackers to deploy additional payloads. The malware primarily targets Windows and Android operating systems and spreads through phishing emails, malicious websites, and private messages.

Known Variants

Known Variants

Variants of LokiBot include Loki-bot, Loki PWS, and Loki Android Trojan. These adaptations exploit varying vulnerabilities and extend their attack surfaces.

Variants of LokiBot include Loki-bot, Loki PWS, and Loki Android Trojan. These adaptations exploit varying vulnerabilities and extend their attack surfaces.

Mitigation Strategies

Mitigation Strategies

Use email filters to block malicious attachments and links
Regularly update software and operating systems to fix security vulnerabilities
Deploy endpoint protection to detect and neutralize malware threats
Enable multi-factor authentication for an added security layer

Targeted Industries or Sectors

Targeted Industries or Sectors

LokiBot's distribution methods, including phishing emails and malicious websites, make it a threat to numerous industries worldwide. It targets sectors indiscriminately, affecting individuals, small businesses, and enterprises in fields such as healthcare, finance, and manufacturing.

LokiBot's distribution methods, including phishing emails and malicious websites, make it a threat to numerous industries worldwide. It targets sectors indiscriminately, affecting individuals, small businesses, and enterprises in fields such as healthcare, finance, and manufacturing.

Associated Threat Actors

Associated Threat Actors

LokiBot is associated with the Nigerian cybercrime group SilverTerrier, known for its expertise in credential theft and phishing schemes. Its accessibility on underground forums makes it a common choice among novice and experienced cybercriminals.

LokiBot is associated with the Nigerian cybercrime group SilverTerrier, known for its expertise in credential theft and phishing schemes. Its accessibility on underground forums makes it a common choice among novice and experienced cybercriminals.

References