Loki is a malware name used in the provided content for multiple distinct families, but the most detailed and recent reporting refers to a Windows backdoor tracked by researchers as Backdoor.Win64.MLoki and associated with the activity cluster Arcane Werewolf / Mythic Likho. Researchers reported discovering this previously unknown Loki backdoor in July 2024 during targeted attacks against more than a dozen Russian companies, including engineering, healthcare, telecom equipment supply, industrial, and later manufacturing organizations. The malware was assessed to be a private Mythic-compatible agent adapted from a Havoc agent, and later reporting stated Loki 2.1 was compatible with both Mythic and Havoc.
In the reported campaigns, Loki was delivered through phishing and socially engineered archives and attachments, including Russian-language filenames and malicious LNK files inside ZIP or RAR archives. Telemetry and filenames indicated delivery via email and user execution; later campaigns used spoofed websites hosting ZIP archives. One infection chain used a malicious LNK to launch PowerShell, which downloaded a Go-based dropper disguised as an image. Earlier related activity also linked Merlin infections to subsequent deployment of Loki 2.0.
Loki is described as a loader-plus-DLL architecture. The loader collects host profiling data including OS version, internal IP address, username, processor architecture, current process path, process ID, and computer name, encrypts the data with AES, and sends it to command-and-control infrastructure over HTTP(S), with some versions additionally Base64-encoding the data. Researchers reported that version 1.0 used HTTP POST, while Loki 2.0 changed transmission to HTTP GET and expanded host profiling by adding the username. The C2 then returns a DLL payload that is loaded in memory and executed via its exported Start function. The main module stores supported command names as hashes rather than plaintext and supports commands including cd, kill-process, create-process, bof, env, pwd, sleep, token, download, inject, exit, and upload. Reporting on Loki 2.1 states the loader can inject code, upload files, exfiltrate data, and terminate processes.
The malware inherits anti-analysis and evasion techniques from Havoc, including encrypted memory images, indirect API calls, and API resolution by hashes. Researchers also noted Loki uses a modified djb2 hashing algorithm with seed 2231 instead of Havoc’s 5381. The operators supplemented Loki with third-party tunneling tools because Loki did not natively support traffic tunneling; ngrok and modified in-memory gTunnel instances were observed on infected systems.
Associated infrastructure and indicators directly mentioned in the content include C2 URLs and domains such as y[.]nsitelecom[.]ru/certcenter, document[.]info-cloud[.]ru/data, ui[.]telecomz[.]ru/data, pop3.gkrzn[.]ru, and mail.gkrzn[.]ru. Reported sample hashes include loader SHA256 81801823c6787b737019f3bd9bd53f15b1d09444f0fe95fad9b568f82cc7a68d and ff605df63ffe6d7123ad67e96f3bc698e50ac5b982750f77bbc75da8007625bb, main module SHA256 aa544118deb7cb64ded9fdd9455a277d0608c6985e45152a3cbb7422bd9dc916, and a Loki 2.0 sample MD5 124D2CB81A7E53E35CC8F66F0286ADA8.
The content also references other malware families named Loki, including a credential stealer associated with CVE-2017-11882 campaigns and botnet C2 activity, and a ransomware reference in a podcast transcript. Because the name is overloaded, the high-confidence characterization from the supplied material is that the primary current Loki is a Windows backdoor/private Mythic-Havoc-compatible implant used in targeted phishing-led intrusions against Russian organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-11882 ... Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 ... Products Associated Malware: Loki, FormBook, Pony/FAREIT | CVE-2017-11882 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Products Associated Malware: Loki, FormBook, Pony/FAREIT Mitigation: Update affected Microsoft products with the latest security patches
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Так, например, один из экземпляров Merlin, попавших к нам в обработку, — с хэш-суммой 6B16D1C2D6D749C8B0E7671E9B347791 и командным центром mail.gkrzn[.]ru — загружал в систему жертвы образец Loki новой версии 2.0 ...
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on telemetry and the names of files in which the malware was detected ... we can assume that in several cases, Loki reaches victims’ computers via email, with an unsuspecting user launching the file themselves.
Malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. | According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets. | Malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets.
The evidence includes a backdoor, preserved on Hedges’ machine, that has also been used by Turla. The backdoor, known as LOKI2, was used by the Moonlight Maze attackers to maintain persistence on Linux machines.
Malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets. | U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2012-0158, CVE-2018-4878, CVE-2017-8759, and CVE-2015-1641. According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. | U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600. According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. | U.S. Government reporting has identified the top 10 most exploited vulnerabilities... malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology... the three vulnerabilities used most frequently across state-sponsored cyber actors from China, Iran, North Korea, and Russia are CVE-2017-11882, CVE-2017-0199, and CVE-2012-0158. | U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
Today I am writing a blog about Decrypting malware strings using 2 ways... The key used was 0x5F5F5F5F.
Processing command hashes ... 0x88BD45B4 inject Inject code into an already running process
Processing command hashes ... 0x5A41B798 token Manage Windows access tokens
Upon execution, the Loki loader generates a packet containing information about the infected system ... and sends it encrypted to the command-and-control (С2) server ... In response, the server sends a DLL, which the loader places in the infected device’s memory – command processing and further communication with the C2 server occur within this library.
The agent itself does not support traffic tunneling, so to access private network segments, attackers use third-party publicly available utilities. On several infected machines, the ngrok utility was found ... In other cases, instances of the gTunnel utility were discovered...
Processing command hashes ... 0x7BD1668F download Send a file from the infected machine to the server ... 0xA4E0A13C upload Send a file from the server to the infected machine | In response, the server sends a DLL, which the loader places in the infected device’s memory ... As a result of the first request to the C2 server, the server returns a payload in the form of a DLL with two exported functions...
68 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware used by Arcane Werewolf, capable of gathering system information, exfiltrating data, injecting code, uploading files, and terminating processes. The latest version (2.1) integrates with Mythic and Havoc post-exploitation frameworks, increasing its flexibility and threat level.
Кастомный агент/бэкдор, совместимый с Mythic. Передает на сервер данные о системе и своей сборке; версия 2.0 расширяет набор собираемых данных именем пользователя и меняет способ отправки данных с POST на GET.
Email-delivered ransomware (attachment-based execution) discussed as prevalent in earlier waves of ransomware, with relatively small per-infection ransom demands (e.g., $300 in Bitcoin) and typically impacting single endpoints rather than whole enterprises.
The post demonstrates two methods for decrypting strings from a malware sample referred to as Loki: emulating its decryption routine with Dumpulator and reproducing the routine in Python using a simple XOR key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.