logo

LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials

ID: 3d688798-39aa-5d45-be71-c58d81faff04

STIX ID: report--3d688798-39aa-5d45-be71-c58d81faff04

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Tushar Subhra Dutta

...
...

LokiBot has resurfaced in a multi-stage phishing campaign that begins with an obfuscated JScript email attachment which decodes a PowerShell stage to load a ConfuserEx-protected .NET injector in memory and perform process injection into aspnet_compiler.exe; the malware harvests credentials from numerous applications, compresses and exfiltrates them to 3DES-protected C2 endpoints, and the report provides multiple IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.