logo

LokiBot Malware Uses API Hashing and 3DES-Encrypted C2 to Hide Infostealer Activity

ID: 03d55d66-a27b-5128-bc55-783a120726d1

STIX ID: report--03d55d66-a27b-5128-bc55-783a120726d1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Mayura Kathir

...
...

LokiBot is an enduring infostealer that uses obfuscated JScript/PowerShell staging, API hashing, and 3DES-encrypted C2 configuration to deliver a reflective .NET loader which injects a 32-bit PE into aspnet_compiler.exe; it harvests credentials from browsers, wallets, and clients, exfiltrates data over HTTP, and the report includes technical analysis, detection opportunities, and IOCs (IPs, domains, URLs, SHA256 hashes).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.