Researchers documented how LokiBot operators deploy and run their command-and-control infrastructure, showing that the malware’s PHP-based panels commonly expose a gate for receiving stolen data and an administrative interface for operators. Analysis of 1,960 real-world panel URLs found that about 95% used the obfuscated entry point PvqDq929BSx_A_D_M1n_a.php, while many deployments relied on plain HTTP rather than HTTPS. Separate traffic analysis tooling also showed Loki-Bot exfiltrating credentials and application data over HTTP POST requests to C2 paths such as ver.php, reinforcing that the malware’s network activity can often be parsed and tracked in transit.
A newer Loki sample also used a heavily obfuscated, multi-stage infection chain to hide delivery and execution. The attack began with an HTA file that concealed a PowerShell downloader through layered URL encoding, Base64, and character substitution; that downloader fetched a VBS script, which then retrieved an image from Google Drive containing a steganographically hidden, reversed Base64 payload. The decoded .NET assembly was injected into aspnet_regbrowsers.exe, after which the malware contacted C2 infrastructure and attempted to deploy additional payloads, highlighting recurring Loki tradecraft around phishing delivery, script-based loaders, steganography, and covert credential theft.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
An example PCAP shows Loki-Bot version 1.8 exfiltrating application and credential data from a Windows 8.1 workstation to 185.141.27.187 over HTTP POST to /danielsden/ver.php. The transmission is timestamped as the first observed send in the sample traffic.
LokiBot was first advertised in underground forums in 2015 as an information stealer and keylogger, marking its emergence as a malware offering.
A Loki information-stealing malware sample analyzed by Logpoint was discovered on MalwareBazaar among recent malware uploads, providing the basis for analysis of its infection chain.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
logpoint.com
Open sourcevirusbulletin.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.