Loki Bot is a long-running Windows credential-stealing malware family widely known for harvesting passwords and other sensitive data from infected systems. It is commonly characterized as an infostealer and has been advertised in criminal forums as a password and cryptocurrency-wallet stealer. Its collection scope includes credentials and data from web browsers, messaging applications, email clients, FTP clients, password managers, cryptocurrency wallets, and numerous other desktop applications. Reported variants have also stolen configuration data from Microsoft Outlook and files associated with note-taking applications such as Stickies.
Loki Bot is typically delivered through phishing and malspam campaigns using social-engineering lures such as invoices, payment notices, fake notifications, orders, and commercial offers. Observed delivery mechanisms include malicious PDF lures that direct victims to download an executable, ISO attachments sent to corporate mailboxes, and exploit-document campaigns in which builder kits such as ThreadKit distribute Loki Bot through Microsoft Office vulnerabilities. The malware has also appeared as a payload concealed by .NET packers such as Hectobmp, reflecting its use in broader crimeware distribution ecosystems.
Once executed, Loki Bot variants have been observed establishing persistence by copying themselves into user-profile locations and creating startup-launched scripts. Some samples employ runtime API resolution and other anti-analysis measures to hinder reverse engineering. After collecting host information and stolen credentials or files, Loki Bot exfiltrates the data to operator-controlled infrastructure, commonly via HTTP POST, with some observed traffic using compression. The malware has been used extensively in financially motivated campaigns and has frequently targeted business users and corporate environments because of the value of harvested authentication material and related sensitive information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Loki-Bot is advertised as a Password and CryptoCoin Wallet Stealer on several hacker forums
The author of the malware has written a number of functions for stealing credentials from a victim’s machine.
Browser software: Mozilla Firefox, IceDragon, Safari, K-Meleon, Mozilla SeaMonkey, Mozilla Flock, NETGATE Black Hawk, Lunascape, Comodo Dragon, Opera Next, QtWeb, QupZilla, Internet Explorer, Opera, 8pecxstudios, Mozilla Pale Moon, Mozilla Waterfox.
The malware steals png and rtf files from the sub-folders “\stickies\images” and “\stickies\rtf” in several system directories, such as %AppData%, %UserProfile%.
Loki-Bot is advertised as a Password and CryptoCoin Wallet Stealer on several hacker forums
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential and cryptocurrency wallet stealer malware advertised on hacker forums; the paper focuses on its characteristics, capabilities, and inner workings based on code-level analysis.
An information-stealing malware family recovered as the final payload from a Hectobmp sample.
A password stealer mentioned as an example of malware whose backend processing of stolen SQLite files could itself become an attack surface.
https://www.proofpoint.com/us/threat-insight/post/unraveling-ThreadKit-new-document-exploit-builder-distribute-The-Trick-Formbook-Loki-Bot-malware
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.