A recent phishing campaign is delivering LokiBot through malicious email attachments containing obfuscated JScript, reviving the long-running infostealer with a multi-stage infection chain designed to evade detection. The script runs via Windows Script Host, decodes a PowerShell loader, and decrypts a ConfuserEx-protected .NET injector that reflectively loads into memory before injecting the final payload into aspnet_compiler.exe using Windows APIs including CreateProcessA, VirtualAllocEx, WriteProcessMemory, SetThreadContext, and ResumeThread.
Once executed, the 32-bit LokiBot payload uses API hashing and runtime API resolution, creates a mutex derived from the victim system's MachineGuid, steals credentials from numerous applications, compresses the data with aPLib, and beacons to HTTP command-and-control servers roughly every minute. Researchers said the malware stores C2 addresses with 3DES encryption and noted a flawed persistence mechanism in some newer builder-generated samples, where a patched decryption routine causes the malware to use a C2 URL instead of the intended Run registry path; reported infrastructure includes the IP address 158.94.211.95, and defenders were urged to block script-based attachments and watch for abnormal aspnet_compiler.exe activity.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The reporting says a 2018 source-code leak helped expand LokiBot's reach and development, contributing to its continued use.
The reporting states that LokiBot was first advertised in 2015, marking its emergence as a malware offering.
The analysis found that newer builder-generated samples contained a flawed persistence routine in which a patched decryption function caused the malware to use a C2 URL instead of the intended Run registry path.
LevelBlue reported a recent phishing-driven LokiBot campaign using an obfuscated JScript attachment, a PowerShell loader, a ConfuserEx-protected .NET injector, and process injection into aspnet_compiler.exe to deploy the final payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.