Loki is a Windows-focused information-stealing malware family, also referred to as Loki spyware or Loki infostealer. It harvests credentials and account data from web browsers and FTP clients, cryptocurrency-wallet data, and information from selected desktop applications. Loki has been distributed through malicious spam and targeted phishing campaigns, including archive attachments and weaponized Microsoft Office documents exploiting CVE-2017-11882. Observed delivery chains have used script-based downloaders, layered obfuscation, steganographically concealed payloads, and process hollowing or in-memory process injection to evade detection. Campaigns delivering Loki have targeted organizations in energy, oil and gas, electronics, manufacturing, and other sectors, including South Korean companies. The Loki name is also used for unrelated Android adware and a distinct Mythic- and Havoc-compatible Windows backdoor; these should not be conflated with the Loki information stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI). ... CVE-2017-11882 is a 17-year old memory corruption issue in Microsoft Office ... The flaw resides within Equation Editor (EQNEDT32.EXE) ... A proof-of-concept exploit was released publicly, but this has been fixed by Microsoft’s November Patch Tuesday. | Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The cluster develops and updates its custom malware toolkit, deploying a new Loki 2.1 implant compatible with the Mythic and Havoc post-exploitation frameworks.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
the malware were already present on the devices even before the users received them. The malicious apps were not part of the official ROM supplied by the vendor, and were added somewhere along the supply chain.
The PDF sample only contains one page, shown above, which includes some social engineering content to entice users to download and run the malware.
The Cobalt hacking group also weaponized this security flaw in one of their campaigns in late November, sending out a similarly constructed RTF file. In their previous spear-phishing campaigns, the DLL is a component of the penetration testing tool Cobalt Strike.
The payload is dropped via an HTML Application (HTA) that invokes PowerShell, which then retrieves the information stealer.
Once downloaded, this file is saved as picturewithattitudeeventforallthings.vbs under %user%\AppData\Roaming\ directory. After the VBS file was executed with wscript.exe
Trend Micro uncovered a malicious Rich Text Format (RTF) file exploiting CVE-2017-11882 to deliver the spyware Loki (TSPY_LOKI).
All the APIs being called in this malware are hidden, which will be restored before calling. This increases the difficulty for researchers to analyze it.
Steganography has been applied to the image to conceal additional Base64-encoded instructions.
When this malware is executed the very first time, it copies itself to “%AppData%\subfolder”, and renames it as “citrio.exe” in my test enviroment.
This encoded portion is then reversed, decoded, and the code is injected into the aspnet_regbrowsers.exe process
It eventually uses process hollowing to load and execute the main Loki payload.
The dropped malware is generally able to steal private information, log keyboard strokes and steal browsing data.
The author of the malware has written a number of functions for stealing credentials from a victim’s machine.
Browser software: Mozilla Firefox, IceDragon, Safari, K-Meleon, Mozilla SeaMonkey, Mozilla Flock, NETGATE Black Hawk, Lunascape, Comodo Dragon, Opera Next, QtWeb, QupZilla, Internet Explorer, Opera, 8pecxstudios, Mozilla Pale Moon, Mozilla Waterfox.
The malware steals png and rtf files from the sub-folders “\stickies\images” and “\stickies\rtf” in several system directories, such as %AppData%, %UserProfile%.
The dropped malware is generally able to steal private information, log keyboard strokes and steal browsing data.
Then the injected process further starts to communicate with C2
L’API Telegram Bot est massivement exploitée par des auteurs de malwares comme canal d’exfiltration et de commande/contrôle (C2).
125 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer malware family observed using Telegram as C2/exfiltration infrastructure.
Information-stealing malware used in the campaign; the article groups it with malware capable of stealing private and banking information, logging keystrokes, and stealing browsing data.
Custom malware used by Arcane Werewolf, capable of gathering system information, exfiltrating data, injecting code, uploading files, and terminating processes. The latest version (2.1) integrates with Mythic and Havoc post-exploitation frameworks, increasing its flexibility and threat level.
Custom malware used by Arcane Werewolf consisting of a loader and an implant. The loader collects host information, AES-encrypts and Base64-encodes it, exfiltrates it to C2, retrieves or decrypts an implant, and executes it. The implant supports command execution, file upload/download, process creation, code/DLL injection, BOF execution, token management, environment enumeration, directory changes, and process termination.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.