Researchers identified a previously unknown backdoor called Loki that was used in targeted intrusions against more than a dozen Russian companies. The malware appears to be a private agent compatible with the Mythic C2 framework and derived from a Havoc agent, with delivery likely occurring through socially engineered email attachments and archive files bearing Russian-language filenames. Investigators said Loki functions as a loader-and-DLL malware chain: the loader collects host profiling data, encrypts it, and sends it to command-and-control infrastructure, which then returns an in-memory DLL payload responsible for executing attacker commands.
The malware includes multiple anti-analysis and evasion features inherited from Havoc, including encrypted memory, indirect API calls, and hashed API resolution, while also using a modified djb2 hash seed. Researchers also found several loader variants, active C2 infrastructure, and the use of public tunneling tools such as ngrok and a memory-loaded gTunnel component to reach private network segments. Attribution remains unresolved because the operators relied heavily on public tooling and individualized targeting rather than uniquely identifiable tradecraft.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers discovered a previously unknown backdoor named Loki in July 2024 and identified it as a private Mythic-compatible variant derived from a Havoc agent.
Researchers documented Loki's loader-plus-DLL architecture, encrypted host profiling, in-memory payload delivery, anti-analysis features inherited from Havoc, multiple loader variants, active C2 infrastructure, and use of tools including ngrok and gTunnel.
The Loki malware was used in targeted attacks against more than a dozen Russian companies, likely delivered through socially engineered email attachments and archives with Russian-language filenames.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.