LoFiSe is a Windows file-collection malware component used in espionage operations, notably in activity attributed to ToddyCat. It is designed to identify, gather, and stage files of interest from compromised systems for later exfiltration. Reported behavior includes automated collection from the working directory on a recurring schedule, local staging of candidate files, and packaging of collected material into password-protected ZIP archives. LoFiSe has also been described as monitoring filesystem changes and targeting common document and email file types while excluding larger files, indicating a focused collection role rather than broad destructive or disruptive functionality.
Operationally, LoFiSe has been executed via DLL side-loading using a legitimate application, and ATT&CK mappings associate it with DLL hijacking execution flow. Its staged archives are intended for onward transfer by separate exfiltration tooling, making it part of a larger collection-and-exfiltration pipeline rather than a standalone remote access platform. The malware has been observed saving files for evaluation and staging in temporary or program-data locations before archiving them. Its known use aligns with targeted data theft against high-value organizations in Europe and Asia in ToddyCat intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“LoFiSe: This is a component designed to find and collect files of interest on targeted systems.”
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Confucius has used a file stealer to steal documents and images... Patchwork developed a file stealer to search C:\ and collect files with certain extensions... Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
File collection DLL (DsNcDiag.dll) side-loaded via legitimate signed executables; monitors filesystem changes across drives, filters by size/path/extension, hashes (MD5) and tracks collected files in a SQLite DB (Date.db), and periodically packages collected documents into password-protected ZIP archives for later exfiltration.
Utility used for collection/staging: compresses files into ZIP archives prior to exfiltration.
Periodically archives files from the working directory into a password-protected archive for exfiltration.
Malware executed through side-loading under the filename DsNcDiag.dll.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.