LOKI is a cybercriminal threat actor and active ransomware and data-extortion operation observed since at least late 2025. The group appears to have evolved across multiple criminal phases, including cryptocurrency-themed phishing, CTBC-branded financial phishing, and later ransomware-linked data extortion, while reusing infrastructure across those phases. Available reporting supports a high-confidence Iranian nexus based on infrastructure registration details and operator-associated administrative artifacts. LOKI operates a public leak site used to name victims, publish stolen data, and apply extortion pressure. Its extortion workflow includes countdown-based leak logic and public release of victim data after deadlines expire, indicating a structured data-theft extortion model and operation of a dedicated leak site. Reporting directly links the group to theft and publication of sensitive victim information from a U.S. financial services organization, including large-scale exposure of personal and financial records affecting tens of thousands of individuals. The actor’s known victimology in the supplied material centers on the financial sector in the United States. Earlier activity tied to the same infrastructure also indicates phishing operations targeting cryptocurrency users and financial themes. LOKI should therefore be understood as a financially motivated criminal actor with capabilities spanning initial access through phishing and exploitation of exposed internet-facing services, followed by data theft, extortion, and public disclosure. The supplied material does not provide high-confidence evidence of encryption deployment, so LOKI is best characterized here as a ransomware-associated data-extortion actor rather than conclusively as an encrypting ransomware operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware and data extortion operation that evolved from cryptocurrency and financial-sector phishing into active double-extortion activity, publicly leaking stolen victim data via a clearnet leak site and gofile.io links.
Referenced as a cybercrime group associated with a known malicious ZIP file used in the author's test scenario.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.