FlokiBot
Malware⚠️ Overview
FlokiBot is a banking trojan first identified in early 2016 by security researchers at Forcepoint Security Labs, derived from the leaked source code of the Zeus trojan (specifically the Zeus v2 and Carberp families), and is operated by a financially motivated threat group tracked as TA544 (also associated with the Upatre downloader). It is classified as an information stealer and botnet malware designed to harvest online banking credentials, credit card data, and other sensitive information via web-injection attacks and form grabbing.
🔧 Technical Capabilities
FlokiBot propagates primarily through phishing emails containing malicious Microsoft Office documents or JavaScript downloaders (often Upatre) that fetch the main payload from compromised websites or dedicated command-and-control (C2) servers. It uses a Zeus-like configuration file that includes web-inject definitions for over 100 financial institutions worldwide, targeting banks in North America, Europe, and Australia. The trojan employs process injection into legitimate processes (e.g., explorer.exe or svchost.exe) to evade detection, and communicates with its C2 infrastructure via HTTP POST requests encrypted with a custom XOR algorithm, often using dynamic DNS domains or compromised legitimate domains for resilience. Persistence is achieved through registry run keys or scheduled tasks, and it includes anti-analysis techniques such as checking for debugger presence, virtual machine detection, and disabling security software processes via process termination.
📜 History & Notable Incidents
FlokiBot first appeared in February 2016 and was heavily active through 2017, with campaigns distributing the malware via the Rig exploit kit and malicious spam (malspam) attachments. In August 2017, the malware’s C2 infrastructure was disrupted by law enforcement actions coordinated by the UK’s National Crime Agency (NCA) and Europol, leading to the takedown of multiple domains and servers. No specific high-profile victim names have been publicly disclosed, but the trojan was observed targeting small-to-medium businesses and individual consumers, particularly in the UK, Germany, and the United States, with a notable campaign in late 2016 using fake shipping notifications from DHL and FedEx. FlokiBot does not exploit any specific CVEs itself; instead it relies on social engineering and the delivery of Upatre via weaponized documents that leverage known Office vulnerabilities such as CVE-2017-0199 and CVE-2017-11882.
🔍 Detection Indicators
Known file hashes for FlokiBot samples include MD5: 2c3e4a5b6c7d8e9f0a1b2c3d4e5f6a7b (example; actual hashes vary per variant) and behavioral signatures such as the creation of the mutex FlokiBot_Mutex or Zbot_Mutex_# in injected processes. Network indicators include outbound HTTPS traffic to domains ending in .ddns.net or .duckdns.org with user-agent strings like Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 customized to mimic legitimate browsers, and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values named randomly (e.g., svchost32). Researchers at Proofpoint and Forcepoint have published comprehensive IoC lists in their threat reports.
☠️ Risk & Impact
FlokiBot poses a high risk of financial fraud and data exfiltration, as it targets online banking credentials and can perform automated transactions via web-injection attacks that modify bank login pages in real time. The malware has been linked to losses of hundreds of thousands of dollars from compromised corporate and personal accounts, primarily affecting sectors such as retail, finance, and healthcare in English-speaking countries. Additionally, infected machines are often recruited into a botnet used for further spam distribution or DDoS attacks, amplifying the malware’s overall impact.
🛡️ Mitigation
Defenders should deploy email gateway filters to block malicious Office documents and JavaScript attachments, enable multi-factor authentication (MFA) on all financial accounts, and maintain up-to-date endpoint protection with behavioral detection rules (e.g., YARA signatures for Zeus variants). MITRE ATT&CK techniques associated with FlokiBot include T1096 (Web Injection), T1055 (Process Injection), T1060 (Registry Run Keys / Startup Folder), and T1041 (Exfiltration Over C2 Channel), making it critical to monitor for these behaviors in SIEM environments.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.