LOKI2 is a Unix covert-channel backdoor and information-tunneling utility originally published in Phrack in 1997 by daemon9/route and associated with Alhambra. It was presented as a proof-of-concept demonstrating how common network protocols can be abused to conceal command-and-control traffic, but it has also been used operationally in intrusions. LOKI2 tunnels shell commands and command output inside ICMP echo traffic and DNS lookup query and reply traffic over UDP, allowing remote command execution while blending into ostensibly legitimate network activity. The daemon executes received commands through a shell, supports multiple concurrent clients, and includes optional protocol swapping between ICMP and UDP. It supports plaintext operation, weak XOR obfuscation, and a stronger mode using Diffie-Hellman key exchange with Blowfish encryption. The design lacks authentication, meaning any client able to reach the daemon can interact with it or terminate it.
LOKI2 supports multiple Unix-like platforms, including Linux, Solaris, FreeBSD, and OpenBSD, and requires raw-socket access with elevated privileges. Historically, it became notable beyond its proof-of-concept origins because Moonlight Maze operators adopted and modified LOKI2-derived tooling as part of their Unix-focused espionage toolkit in the late 1990s. In that campaign, LOKI2 variants were used as covert backdoors for persistence and command tunneling on compromised systems, with later variants adding stealth improvements, file-transfer capability, and log-cleaning functionality. Subsequent research has also linked the Linux backdoor Penquin Turla to LOKI2-derived code, making LOKI2 an important ancestor in the malware lineage associated with long-running Russian-speaking cyber-espionage activity. Its significance lies in both its early demonstration of covert protocol abuse and its later reuse and adaptation in real-world espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Similarly, the attackers found another favorite in LOKI2. The small tool was an ingenious covert channel backdoor written by Alhambra and daemon9 and published in Phrack from 1996-1997.
Implementation of the Loki 2 ICMP information-tunneling backdoor source code published in Phrack 1996-1997.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
WEAK_CRYPTO (XOR)... To the network protocol analyzer, this traffic seems like ordinary benign packets of the corresponding protocol.
we tunnel simple shell commands inside of... DNS namelookup query / reply traffic
we tunnel simple shell commands inside of ICMP_ECHO / ICMP_ECHOREPLY... traffic
LOKI2 is an information-tunneling program... we tunnel simple shell commands inside of ICMP_ECHO / ICMP_ECHOREPLY and DNS namelookup query / reply traffic. To the network protocol analyzer, this traffic seems like ordinary benign packets of the corresponding protocol.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source backdoor for covert exfiltration. The content describes it as the code basis for Penquin Turla and notes its use for covert channel communications.
A backdoor used to maintain persistence on Linux/Unix systems. The article says it was used by the Moonlight Maze attackers and that Turla later used a modified version as a fallback tool to regain access through Unix servers.
A covert channel/backdoor tool that tunnels shell commands and command output inside ICMP echo/echo-reply and DNS query/reply traffic, allowing remote command execution while masquerading as benign network traffic. It supports plaintext, XOR obfuscation, or stronger cryptography using Diffie-Hellman key exchange and Blowfish.
An ICMP-based covert-channel backdoor used for stealthy command-and-control and file movement. Multiple Moonlight Maze variants were observed, including modified versions that removed obvious lokid references, changed command syntax, and added put/get functionality for direct file transfer and exfiltration between compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.