ATT&CKReferencesTalos Lokibot Jan 2021

Talos Lokibot Jan 2021

Muhammad, I., Unterbrink, H.. (2021, January 6). A Deep Dive into Lokibot Infection Chain. Retrieved August 31, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1053
Scheduled Task/Job
MalwareLokibot

Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution.

T1053.005
Scheduled Task
MalwareLokibot

Lokibot embedded the commands schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I inside a batch script.

T1055.012
Process Hollowing
MalwareLokibot

Lokibot has used process hollowing to inject itself into legitimate Windows process.

T1059.001
PowerShell
MalwareLokibot

Lokibot has used PowerShell commands embedded inside batch scripts.

T1059.003
Windows Command Shell
MalwareLokibot

Lokibot has used cmd /c commands embedded within batch scripts.

T1059.005
Visual Basic
MalwareLokibot

Lokibot has used VBS scripts and XLS macros for execution.

T1070.004
File Deletion
MalwareLokibot

Lokibot will delete its dropped files after bypassing UAC.

T1071.001
Web Protocols
MalwareLokibot

Lokibot has used HTTP for C2 communications.

T1083
File and Directory Discovery
MalwareLokibot

Lokibot can search for specific files on an infected host.

T1105
Ingress Tool Transfer
MalwareLokibot

Lokibot downloaded several staged items onto the victim's machine.

T1106
Native API
MalwareLokibot

Lokibot has used LoadLibrary(), GetProcAddress() and CreateRemoteThread() API functions to execute its shellcode.

T1112
Modify Registry
MalwareLokibot

Lokibot has modified the Registry as part of its UAC bypass process.

T1140
Deobfuscate/Decode Files or Information
MalwareLokibot

Lokibot has decoded and decrypted its stages multiple times using hard-coded keys to deliver the final payload, and has decoded its server response hex string using XOR.

T1204.002
Malicious File
MalwareLokibot

Lokibot has tricked recipients into enabling malicious macros by getting victims to click "enable content" in email attachments.

T1497.003
Time Based Checks
MalwareLokibot

Lokibot has performed a time-based anti-debug check before downloading its third stage.

T1548.002
Bypass User Account Control
MalwareLokibot

Lokibot has utilized multiple techniques to bypass UAC.

T1566.001
Spearphishing Attachment
MalwareLokibot

Lokibot is delivered via a malicious XLS attachment contained within a spearhpishing email.

T1620
Reflective Code Loading
MalwareLokibot

Lokibot has reflectively loaded the decoded DLL into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.