Multiple security reports documented LokiBot/Loki Info Stealer campaigns delivered through phishing emails that used a wide range of attachment types and exploit chains, including LZH, ACE, RAR, PDF, DOCX, RTF, and Excel-based lures. The messages commonly impersonated business documents such as payment confirmations, invoices, shipment notices, and purchase orders, while some samples abused PDF OpenAction, embedded URI actions, malicious macros, or exploits including CVE-2016-0189, CVE-2017-11882, CVE-2021-40444, and CVE-2022-30190 to download or launch the malware. Researchers also observed compromised infrastructure hosting downloaders and payloads, along with HTTP POST traffic to attacker-controlled command-and-control endpoints.
Once executed, LokiBot used layered evasion and execution techniques such as process hollowing, shellcode loaders, API hashing, anti-debugging, anti-VM checks, obfuscation, and in-memory decryption to avoid detection. The malware established persistence in user profile and startup locations, hid files under %APPDATA%, and stole credentials and data from browsers, FTP clients, email applications, password managers, Windows credentials, Microsoft Outlook registry entries, and even user files such as Stickies notes. Stolen information was compressed and exfiltrated over HTTP, and some variants also supported follow-on commands including downloading additional files, loading DLLs, updating themselves, and self-deleting, underscoring LokiBot’s continued use as a flexible credential-theft platform.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
FortiGuard found a separate MSIL loader, IMG_3360_103pdf.exe, in the same compromised vertebromed[.]md directory. It was created on May 30, 2023 and also loaded LokiBot while connecting to the same C2 IP.
FortiGuard reported that the injector file dhssdf.exe used in the Word-document campaign was created on a compromised website, vertebromed[.]md.
FortiGuard Labs analyzed malicious Microsoft Word documents in May 2023 that exploited CVE-2021-40444 and CVE-2022-30190 to deliver LokiBot. The attack chain used either an external MHTML link or auto-executing VBA macros to download an injector that decrypted and injected the payload, which communicated with 95[.]164[.]23[.]2/swe/h/pin[.]php.
Trend Micro described an aggressive August 2021 campaign delivering LokiBot through PDF, DOCX, RTF, Internet Explorer, and Excel-based lures. One infection chain used a PDF OpenAction request to fetch malicious HTML from 198[.]23[.]212[.]137, exploit CVE-2016-0189, and download a LokiBot payload named vbc.exe.
Infoblox analyzed a Lokibot campaign from early June 2021 that used spoofed invoice-themed phishing emails with RAR archives containing an NSIS installer disguised as a PDF. The installer dropped a loader and encrypted payload, then used in-memory decryption and process hollowing to run Lokibot and exfiltrate data to 173[.]208[.]204[.]37.
On 2018-12-03, SANS Internet Storm Center documented a Lokibot infection delivered by a purchase-quotation spam email carrying the Excel attachment 62509871.xls. When macros were enabled, the spreadsheet downloaded Lokibot from a.doko[.]moe over HTTPS, established persistence via a Registry change and Startup-folder VBS file, and generated post-infection traffic to decvit[.]ga.
Beginning in early July 2018, attackers targeted corporate mailboxes with malicious spam carrying .iso attachments that delivered Loki Bot. The emails used lures such as fake company notifications, financial documents, and commercial offers to steal credentials and other sensitive data from infected systems.
On 2017-06-12, Malware-Traffic-Analysis documented a Lokibot infection delivered by a malspam email spoofing "Amina Diab" with subject "Re: PURCHASE ORDER 457211." The ACE attachment PO12062017.ace contained PO12062017.exe, which installed Lokibot and generated HTTP POST traffic to 192.99.2[.]94.
Infoblox states that Lokibot was first seen on May 3, 2015, following a sales announcement by a hacker using the name Lokistov or Carter.
Trend Micro reported a spam campaign delivering the Loki information stealer through LZH attachments masquerading as bank payment confirmations. The LZH sample dropped an obfuscated executable that used process hollowing, and the final payload matched a previously seen CAB-delivered Loki sample, linking both to the same ongoing campaign.
FortiGuard Labs documented a new Loki Bot variant delivered through a socially engineered PDF that used an embedded URI action to download QUOTATION.exe. The malware established persistence via a VBS launcher in Startup and stole credentials and files from more than 100 applications.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 67 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
sans.org
Open sourcemalware-traffic-analysis.net
Open sourcefortinet.com
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourceisc.sans.edu
Open sourcesecurelist.com
Open sourceblog.fortinet.com
Open sourceinfoblox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.