Lokibot

S0447

Malware.View on attack.mitre.org

About this malware

Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1016
System Network Configuration Discovery

Lokibot has the ability to discover the domain name of the infected host.

T1027
Obfuscated Files or Information

Lokibot has obfuscated strings with base64 encoding.

T1027.002
Software Packing

Lokibot has used several packing methods for obfuscation.

T1033
System Owner/User Discovery

Lokibot has the ability to discover the username on the infected host.

T1041
Exfiltration Over C2 Channel

Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data.

T1053
Scheduled Task/Job

Lokibot's second stage DLL has set a timer using “timeSetEvent” to schedule its next execution.

T1053.005
Scheduled Task

Lokibot embedded the commands schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I inside a batch script.

T1055.012
Process Hollowing

Lokibot has used process hollowing to inject itself into legitimate Windows process.

T1056.001
Keylogging

Lokibot has the ability to capture input on the compromised host via keylogging.

T1059.001
PowerShell

Lokibot has used PowerShell commands embedded inside batch scripts.

T1059.003
Windows Command Shell

Lokibot has used cmd /c commands embedded within batch scripts.

T1059.005
Visual Basic

Lokibot has used VBS scripts and XLS macros for execution.

T1070.004
File Deletion

Lokibot will delete its dropped files after bypassing UAC.

T1071.001
Web Protocols

Lokibot has used HTTP for C2 communications.

T1082
System Information Discovery

Lokibot has the ability to discover the computer name and Windows product name/version.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. CISA Lokibot September 2020 Open source
    DHS/CISA. (2020, September 22). Alert (AA20-266A) LokiBot Malware . Retrieved September 15, 2021.
  2. Infoblox Lokibot January 2019 Open source
    Hoang, M. (2019, January 31). Malicious Activity Report: Elements of Lokibot Infostealer. Retrieved May 15, 2020.
  3. Morphisec Lokibot April 2020 Open source
    Cheruku, H. (2020, April 15). LOKIBOT WITH AUTOIT OBFUSCATOR + FRENCHY SHELLCODE. Retrieved May 14, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.