LOBSHOT is a Windows hidden virtual network computing (hVNC) remote-access trojan and information stealer active since at least July 2022. It has been distributed through malvertising campaigns in which fraudulent software-download sites and malicious installers impersonate legitimate applications. The malware performs host reconnaissance, including collection of system, user, display, process, desktop, and virtualization-related information, and searches Chrome, Edge, and Firefox for installed cryptocurrency-wallet extensions. LOBSHOT establishes user-level persistence, relocates itself to obscure execution ancestry, dynamically resolves Windows APIs, and includes checks intended to avoid Microsoft Defender emulation environments. Its hVNC component creates a separate hidden Windows desktop on which it can launch processes and browsers, capture the display, execute commands, simulate keyboard and mouse input, and manipulate clipboard content without visible interaction on the victim’s normal desktop. LOBSHOT has been used in financially motivated intrusions, including activity attributed to Hive0117, and has also been observed as a payload delivered by CastleLoader campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In one analyzed attack, FMVT RAT also downloaded LOBSHOT, a RAT with HVNC support that enables covert control of a separate virtual desktop on the infected machine.
"LOBSHOT appears to be leveraged for financial purposes employing banking trojan and info-stealing capabilities" and its core capability is an hVNC module providing stealthy remote control.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
This malware hides its primary strings through a straightforward encryption function using different bitwise operators.
It employs dynamic import resolution to evade security products and slow down the rapid identification of its capabilities.
Attackers promoted their malware using an elaborate scheme of fake websites through Google Ads and embedding backdoors in what appears to users as legitimate installers.
After LOBSHOT is executed, it moves a copy of itself to the C:\ProgramData folder, spawning a new process using explorer.exe, terminating the original process, and finally deleting the original file.
LOBSHOT builds a custom structure containing enumerated data from the machine including ... username, computer name.
LOBSHOT builds a custom structure containing enumerated data ... number of processes running, process ID, parent process of malware.
It starts by targeting specific Google Chrome extensions that deal with cryptocurrency wallets ... trying to access 32 Chrome wallet extensions, nine Edge wallet extensions, and 11 Firefox wallet extensions.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote-access trojan with HVNC capability, enabling an operator to invisibly control a separate virtual desktop on an infected host.
A VNC-based remote viewer observed as a final payload in the Urutyka campaign, likely as a variant of Lobshot.
A malware family referenced via command-and-control infrastructure in the campaign IoCs, indicating association with the broader activity.
A VNC-based remote viewer observed as a downstream payload in the Urutyka campaign, likely used for remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.