LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign
ID: f1c708d8-163a-590f-9445-abff4a8d5ac6
STIX ID: report--f1c708d8-163a-590f-9445-abff4a8d5ac6
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
This report provides a focused technical analysis of a multi-stage LokiBot infostealer campaign delivered via JScript malspam. It documents the execution chain (obfuscated JScript -> Base64 PowerShell -> XOR-decrypted .NET loader -> process injection of a 32-bit LokiBot binary), describes credential-harvesting, persistence attempts, API-hashing and other TTPs, and lists IoCs (SHA256s, IP, domains, and URLs) observed in the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
