Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, it establishes persistence on the system by creating a Scheduled Task named “0BAduEnQZG9POyK”.
the loader proceeds with setting the file attributes of agent.js ... as well as creating the scheduled task named “Firefox Default Browser Agent 458046B0AF4A39CB” via ITaskScheduler interface that runs agent.js file via wscript.exe.
The download batch file “m8hHxtkVLYPw.bat” contains the PowerShell command ... responsible for fetching another payload ... “WLXUL6LWXQPB.js”.
agent1.ps1 ... contains a one-liner command that is responsible for AMSI bypass.
The downloaded JavaScript file is responsible for self-replication... it proceeds to retrieve and execute additional payloads via PowerShell commands.
Additionally, it establishes persistence on the system by creating a Scheduled Task named “0BAduEnQZG9POyK”.
The final loader payload is extracted and decrypted using XOR from the resource section, where the XOR key is also located.
creating the scheduled task named “Firefox Default Browser Agent 458046B0AF4A39CB”
0x6E Performs process injection into either explorer.exe or certutil.exe based on the subsystem value
the program searches for the distinct identifier "LDR," retrieves commands from the C2 server, decodes them from Base64, and decrypts them using XOR with a shared secret as the key.
Additionally, the loader employs an anti-VM capability. It uses EnumDisplayDevicesW to enumerate display devices... checks for specific files related to VirtualBox... inspects certain directories and files for evidence of a VM environment.
It then checks for specific files related to VirtualBox... retrieves the computer name and name of the currently logged-in user... GlobalMemoryStatusEx is called to retrieve the system's memory status.
retrieves the computer name and name of the currently logged-in user
the infected machine sends another request containing the information gathered from the machine, including OSMajorVersion, OSMinorVersion, OSBuildNumber, Username, ComputerName, and the domain name if present.
The loader further inspects certain directories and files for evidence of a VM environment... performs checks on files with extensions like doc, docx, xls, and xlsx.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Koi Loader (also known as Koi Stealer) is a malware family used to load and deploy additional payloads or steal information from infected systems. It was previously distributed via the same initial Google Sites URLs before the switch to NetSupport RAT.
A loader written in C/C++ that establishes persistence, performs anti-CIS and anti-VM checks, checks host characteristics, communicates with C2, and downloads/executes follow-on payloads including PowerShell scripts and Koi Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.