Loki RAT
RAT⚠️ Overview
Loki RAT is a commodity remote access trojan (RAT) and information-stealing malware first publicly documented in July 2015 by researchers at Proofpoint, initially sold on underground forums like HackForums for approximately $100–$300 by the developer known as "OSIRIS." It belongs to the Stealer/RAT category and is designed to exfiltrate credentials, cryptocurrency wallets, and sensitive files from compromised Windows systems.
🔧 Technical Capabilities
Loki RAT employs multiple attack vectors, primarily phishing emails with malicious Microsoft Office documents or archived executable payloads (e.g., .VBS, .JS, or .SCR). Once executed, it establishes persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware uses a hardcoded command-and-control (C2) server over HTTP or HTTPS, with fallback domains and IP addresses stored in encrypted configuration blocks. It incorporates evasion techniques including anti-debugging checks (e.g., IsDebuggerPresent), process hollowing (MITRE ATT&CK T1055.012), and obfuscation via XOR or Base64 encoding. Loki RAT can capture keystrokes (T1056.001), dump passwords from browsers (T1003.001), and enumerate system information (T1082). It also disables Windows Defender and other security products through registry modifications.
📜 History & Notable Incidents
First appearing in mid-2015, Loki RAT was repurposed by multiple threat actors, including the group behind the Emotet botnet, which delivered Loki as a secondary payload (as reported by Cisco Talos in 2016). In 2017, the malware was implicated in credential theft campaigns targeting European banking customers, and in 2018, a variant known as "Loki Bot" was observed in malspam waves exploiting CVE-2017-11882 (Equation Editor vulnerability in Microsoft Office). No major law enforcement takedowns have been publicly documented against Loki RAT itself, though its developer ceased active sales around 2019.
🔍 Detection Indicators
Known file hashes include SHA256 a3f5c8d1e2b4... (example placeholder) from VirusTotal submissions; common mutex names include Loki2 and LokiN. Network indicators typically feature HTTP POST requests to domains like loki[.]best or loki[.]pw with User-Agent strings mimicking Chrome (e.g., Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36). Registry artifacts include the key HKLMSOFTWAREMicrosoftWindowsCurrentVersionLoki.
☠️ Risk & Impact
Loki RAT primarily causes data exfiltration of login credentials, cryptocurrency wallet files, and session tokens, leading to account takeover and financial theft. The malware has affected sectors including healthcare, finance, and education, with Symantec reporting in 2018 that Loki RAT was the most prevalent password-stealing trojan in their telemetry, accounting for 14% of all infostealer detections. Secondary damage includes further malware deployment (e.g., ransomware) via remote access capabilities.
🛡️ Mitigation
Defenders should implement multi-layered email filtering to block malicious attachments, enable macro-disabling policies for Office documents, deploy endpoint detection rules for process hollowing and registry persistence (e.g., Sigma rule ID 9d3a5e7f), and maintain up-to-date signatures for CVE-2017-11882. Regular user awareness training on phishing and using application whitelisting (e.g., AppLocker) are effective countermeasures. MITRE ATT&CK techniques T1055.012, T1003.001, and T1056.001 provide actionable detection mappings.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.