Lofy
Malware⚠️ Overview
Lofy is a remote access trojan (RAT) first documented by cybersecurity firm Trend Micro in early 2022, believed to be operated by a threat actor tracked as TA569, primarily targeting government and defense sectors in Southeast Asia. It is categorized as a commodity RAT capable of full remote control and data theft, often delivered via spear-phishing emails with malicious macro-enabled documents.
🔧 Technical Capabilities
Lofy employs process injection (MITRE ATT&CK T1055) into legitimate Windows processes such as explorer.exe to evade detection, and uses HTTPS-based command and control (T1572) with encrypted payloads to blend with normal traffic. It achieves persistence by creating a scheduled task (T1053.005) or modifying the Windows Run registry key (T1547.001). The malware includes keylogging (T1056.001), screen capture (T1113), and file exfiltration (T1041) modules, and can disable user account control (UAC) via registry manipulation (T1548.002). It also uses dynamic DNS domains for C2 resilience, and its installer often contains obfuscated PowerShell scripts (T1059.001) to download the final payload.
📜 History & Notable Incidents
Lofy was first observed in January 2022 in a campaign targeting Vietnamese government networks, as reported by Kaspersky Labs. No CVEs have been publicly assigned to Lofy itself, as it relies on social engineering and no known zero-day exploits. In March 2023, a wave of attacks using Lofy was linked to Chinese state-sponsored group APT10 by an analysis from Recorded Future, though attribution remains contested.
🔍 Detection Indicators
Indicators of compromise include the mutex name LofyMutex2022 commonly created on infected hosts, and persistent HTTP User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 with specific parameter ordering. Network IOCs include C2 domains using the pattern lofy[.]XXXX[.]com and outbound connections on port 443 to IPs in the 45.63.0.0/16 range. File hashes of known Lofy samples are cataloged in VirusTotal under family tag "Lofy".
☠️ Risk & Impact
Lofy enables full remote control of infected machines, allowing exfiltration of classified documents, credentials, and keystrokes, with documented impacts on national security agencies in Vietnam and the Philippines. Financial losses are difficult to quantify but include costs of incident response and system remediation; the primary risk is intellectual property theft and espionage in the targeted sectors.
🛡️ Mitigation
Organizations should implement email filtering to block macro-enabled attachments, enforce application whitelisting to prevent execution of Lofy’s injected processes, and deploy endpoint detection and response (EDR) rules for process injection and scheduled task creation (e.g., Sigma rule ID 8790). Regular patching of Microsoft Office vulnerabilities is recommended to reduce initial access vectors.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.