Loki: a new private agent for the popular Mythic framework
ID: 9df2c057-7dfa-5eb3-91e2-a34da5fc9a2f
STIX ID: report--9df2c057-7dfa-5eb3-91e2-a34da5fc9a2f
Feed Name: Securelist by Kaspersky
In July 2024 researchers identified a previously unknown Windows backdoor (Backdoor.Win64.MLoki), a private Mythic-compatible agent derived from Havoc, used in targeted attacks against Russian organizations; the report details loader and DLL architecture, command hashing and supported operations (process injection, token manipulation, file upload/download, BOF), encryption and C2 communication (AES+base64, specific domains), sample hashes, use of tunneling tools (ngrok, gTunnel/goReflect), victim indicators, and states attribution is inconclusive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
