Loki (Mythic) is an information-stealing malware first documented in 2015, attributed to the threat actor TA544, and later adapted to use the open-source Mythic C2 framework for encrypted communications. Classified as an infostealer, it primarily targets credentials from web browsers, email clients, FTP applications, and cryptocurrency wallets, as described in MITRE ATT&CK entry S0443.
Loki propagates via phishing emails with malicious macro-enabled documents or executable attachments that download the payload from remote servers. Its C2 infrastructure originally used HTTP, FTP, or SMTP protocols, but recent variants leverage the Mythic framework's AES-encrypted channels to evade network detection. Persistence is achieved through registry Run keys and scheduled tasks. Evasion techniques include packing with UPX, obfuscation via XOR encoding, and disabling security software through process injection. Loki steals browser credential stores (Chrome, Firefox, Edge), FTP client configurations (FileZilla, WinSCP), email client settings (Outlook, Thunderbird), and cryptocurrency wallet directories. It also collects system information for reconnaissance, including hostname, username, OS version, and installed antivirus products.
Loki first appeared in underground crimeware forums in 2015, sold as a modular stealer kit. Major campaigns between 2017 and 2019, documented by Proofpoint and Cisco Talos, targeted financial, healthcare, and manufacturing sectors in Europe and North America, infecting tens of thousands of endpoints. No specific CVEs are associated with Loki, as it relies on social engineering rather than software exploits. Law enforcement actions have not been publicly reported against its operators, though the malware's source code was leaked in 2018, leading to multiple variants.
Known Loki file hashes include SHA256 e4a5c7d1f2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8 (example; real hashes are available on VirusTotal). Behavioral indicators include file writes to %APPDATA%LocalTemp with randomly named .exe files, creation of mutex GlobalLoki_0, and network connections to IP addresses over port 80 or 443 with User-Agent strings mimicking Firefox 60.0. Registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun containing the malware path are common.
Loki exfiltrates stored credentials, enabling account takeovers, data breaches, and financial theft. Organizations with weak email security are at highest risk; losses from credential theft can lead to lateral movement and ransomware deployment. The malware has affected diverse sectors, including finance, healthcare, and manufacturing, as reported by threat intelligence vendors.
Defenders should deploy email gateway filtering to block macro attachments, implement endpoint detection rules for Loki-specific IOCs (e.g., mutex, registry keys, file paths), and enforce multi-factor authentication. Regular security awareness training and application whitelisting reduce infection risk. MITRE ATT&CK S0443 provides additional detection recommendations.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.