LokiBot
LokiBot is a type of malware primarily used for stealing sensitive information from infected systems. It is classified as an information stealer, targeting credentials stored in web browsers, email clients, and other software. LokiBot has been active since at least 2015 and is known for its ability to exfiltrate data efficiently. The malware is often distributed through phishing campaigns and malicious attachments, making it a persistent threat to both individuals and organizations. As of October 2023, LokiBot continues to evolve, incorporating new techniques to evade detection and improve its data-stealing capabilities.
Overview
LokiBot is a well-known information-stealing malware that targets Windows operating systems. It is designed to extract sensitive data such as login credentials, banking information, and other personal details from infected devices. The malware is often delivered through phishing emails, malicious attachments, and compromised websites. LokiBot is popular among cybercriminals due to its effectiveness and ease of use, often being sold on underground forums. It is continually updated to bypass security measures and remain undetected by antivirus software.
History
LokiBot first emerged in 2015 and quickly gained notoriety for its ability to steal a wide range of information from infected systems. Over the years, it has undergone several updates to enhance its functionality and evade detection. The malware's source code was leaked in 2016, to an increase in its distribution and the development of various modified versions. LokiBot has been involved in numerous cybercriminal campaigns, often targeting businesses and individuals across different sectors. Its continued evolution demonstrates the adaptability of cybercriminals in response to advancements in security technologies.
Technical characteristics
LokiBot is primarily written in C++ and is known for its modular architecture, allowing it to perform various malicious activities. The malware typically operates by injecting itself into legitimate processes to avoid detection. Once executed, LokiBot searches for stored credentials in web browsers, email clients, and other applications. It can also capture keystrokes and take screenshots to gather additional information. The stolen data is then exfiltrated to a command and control (C2) server controlled by the attackers. LokiBot employs various techniques to evade detection, such as using encryption to protect its communications and employing anti-analysis measures to hinder reverse engineering.
Infection vector
LokiBot is commonly distributed through phishing emails that contain malicious attachments or links. These emails often impersonate legitimate organizations or individuals to trick recipients into opening the attachments or clicking on the links. Once the attachment is opened or the link is clicked, the malware is downloaded and executed on the victim's system. LokiBot can also be spread through compromised websites that host malicious scripts designed to exploit vulnerabilities in the visitor's browser or operating system. Additionally, the malware may be bundled with legitimate software downloads from untrusted sources.
Notable campaigns
LokiBot has been involved in numerous cybercriminal campaigns targeting various sectors, including finance, healthcare, and manufacturing. One notable campaign occurred in 2018 when LokiBot was used in a phishing campaign targeting businesses in the United States. The attackers sent emails with malicious attachments disguised as invoices, luring recipients into opening them and inadvertently installing the malware. Another significant campaign took place in 2020, where LokiBot was distributed through a fake COVID-19 information website. The site claimed to provide updates on the pandemic but instead delivered the malware to unsuspecting visitors.
Detection and mitigation
Detecting LokiBot can be challenging due to its use of evasion techniques and frequent updates. However, several measures can help identify and mitigate the threat. Organizations should implement robust email filtering solutions to block phishing emails and malicious attachments. Regularly updating antivirus software and operating systems can help detect and prevent infections. User education is also crucial, as it can reduce the likelihood of users falling victim to phishing scams. Implementing network monitoring tools can help detect unusual traffic patterns indicative of data exfiltration. Additionally, organizations should employ multi-factor authentication to protect sensitive accounts and limit the damage caused by credential theft.
LokiBot Evolution Timeline
LokiBot Distribution Methods
See also
- Information Stealer
- Phishing
- Malware
- Cybersecurity