LOLSnif is a credential-stealing backdoor first publicly documented by Trend Micro in August 2022, attributed to the threat group TA558 (also tracked as APT36 by some vendors). It belongs to the categories of backdoor and information stealer, primarily targeting government, military, and energy sectors in South Asia.
The malware propagates via spear-phishing emails containing weaponized Microsoft Office documents (CVE-2017-0199 and CVE-2018-0802 exploits) that drop a malicious HTA file. The HTA executes PowerShell (MITRE ATT&CK ID T1059.001) to download the main payload from a remote C2 server over HTTPS. Persistence is achieved through Windows Management Instrumentation (WMI) event subscriptions (T1546.003) and registry Run keys (T1547.001). For evasion, LOLSnif relies heavily on living-off-the-land binaries (LOLBins) such as certutil for base64 decoding and mshta for script execution, avoiding file-based disk artifacts. The C2 infrastructure uses HTTP with JSON-encoded command responses and a custom user-agent string mimicking legitimate browser traffic (Mozilla/5.0 Windows NT 10.0; Win64; x64).
First observed in Q1 2022, LOLSnif was used in campaigns against Philippine government agencies in April 2022, as reported by Trend Micro. A subsequent campaign in late 2022 targeted Indian energy companies, leveraging fake job offer documents. No specific CVEs are directly associated with the malware itself, but it exploits older Office vulnerabilities. Law enforcement actions have not been publicly documented.
Known network IOCs include C2 domains ending in .top and .xyz (e.g., microsoftupdate[.]top). File hashes for initial droppers have been published in Trend Micro’s threat analysis (SHA256: 2a3e...). Behavioral indicators include the execution of certutil -decode followed by mshta from temporary directories. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to WMI event filters are also suspicious.
LOLSnif exfiltrates stored credentials from browsers and email clients, as well as sensitive documents located on local drives and network shares. The data is compressed into ZIP archives and uploaded to the C2 server. Affected sectors include government, military, and energy in South Asia, with potential for lateral movement and establishment of persistent access.
Deploy endpoint detection rules (e.g., YARA rules from Trend Micro) for LOLBin abuse and PowerShell script blocks. Enforce application whitelisting to block mshta and certutil unless explicitly required, and maintain updated email security gateways to filter phishing attachments. Block known C2 domains and monitor WMI event subscriptions (MITRE ATT&CK ID T1546.003) for persistence anomalies.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.