logo

LokiBot After a Decade: An Analysis of a Recent LokiBot Campaign

ID: f1c708d8-163a-590f-9445-abff4a8d5ac6

STIX ID: report--f1c708d8-163a-590f-9445-abff4a8d5ac6

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
70/100

Date Published: 2026-06-24

Date Updated: 2026-07-19

Author: Dawid Nesterowicz

...
...

This report provides a focused technical analysis of a multi-stage LokiBot infostealer campaign delivered via JScript malspam. It documents the execution chain (obfuscated JScript -> Base64 PowerShell -> XOR-decrypted .NET loader -> process injection of a 32-bit LokiBot binary), describes credential-harvesting, persistence attempts, API-hashing and other TTPs, and lists IoCs (SHA256s, IP, domains, and URLs) observed in the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.