Elastic Security Labs identified LOBSHOT as a malware family that combines credential theft with a hidden virtual network computing capability, allowing attackers to remotely control infected systems through hVNC while remaining invisible to the user. Researchers said the malware’s command-and-control traffic includes hardcoded data that can serve as a hunting signature, giving defenders a way to identify related samples and infrastructure.
Follow-on analysis found code overlap with DarkVNC, although researchers cautioned that the similarity may reflect shared hVNC components rather than firm attribution. Additional triage linked LOBSHOT to more than 550 VirusTotal samples over the prior year, with the earliest identified specimens dating to late July 2022, indicating sustained development and operational use; extracted configurations also revealed multiple C2 IP addresses, most commonly communicating over TCP port 443.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
OpenAnalysis released further technical analysis of LOBSHOT, including code-overlap observations with DarkVNC, a configuration-extraction script, and multiple recovered command-and-control endpoints. The post also noted that Elastic's hardcoded-byte hunting pattern returned more than 550 VirusTotal samples from the prior year.
Elastic Security Labs published its discovery and analysis of the malware family it internally named LOBSHOT. The malware was described as an hVNC-based bot with information-stealing and hidden VNC remote-access capabilities.
OpenAnalysis reported that the earliest samples matching Elastic's cited LOBSHOT hunting pattern appeared in late July 2022, indicating the malware had been active by then.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.