logo

Arcane Werewolf Hacker Group Added Loki 2.1 Malware Toolkit to their Arsenal

ID: 91315efe-ae57-57b6-be82-8d2e7237ac9f

STIX ID: report--91315efe-ae57-57b6-be82-8d2e7237ac9f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Arcane Werewolf (Mythic Likho) launched targeted phishing campaigns in Oct–Nov 2025 against Russian manufacturing firms using a new Loki 2.1 implant delivered via ZIP archives containing LNK shortcuts. The attack chain uses PowerShell to fetch a Go-language dropper that decodes and executes a loader (chrome_proxy.pdf) which collects system metadata, can inject code, terminate processes, exfiltrate AES-encrypted data over HTTPS, and integrates with Mythic and Havoc post-exploitation frameworks—demonstrating active, sophisticated targeting and ongoing malware development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.