LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials
ID: 3d688798-39aa-5d45-be71-c58d81faff04
STIX ID: report--3d688798-39aa-5d45-be71-c58d81faff04
Feed Name: cybersecurityNews.com
Threat Score
LokiBot has resurfaced in a multi-stage phishing campaign that begins with an obfuscated JScript email attachment which decodes a PowerShell stage to load a ConfuserEx-protected .NET injector in memory and perform process injection into aspnet_compiler.exe; the malware harvests credentials from numerous applications, compresses and exfiltrates them to 3DES-protected C2 endpoints, and the report provides multiple IoCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
