Netskope Threat Labs

Loki

ATP Sandbox Adv. HeuristicsAV

Loki is an information stealer and keylogger that harvests saved passwords, browser data, and application credentials from infected systems. It has circulated in criminal markets for years, and its operators bundle it with loaders and fake software to collect data at scale. Detections under this name indicate that an implant captured authentication material, which should trigger credential resets for affected accounts.

First seen
March 2022
Last seen
October 2026
loki
Alert Name
Android.Trojan.Loki
ByteCode-MSIL.Ransomware.Loki
Document-Word.Trojan.Loki
Dropped:Trojan.Ransom.Loki.CSB
Dropped:Trojan.Ransom.Loki.DEM
Dropped:Trojan.Ransom.Loki.GGA
Gen:Variant.Ransom.Loki.10112
Gen:Variant.Ransom.Loki.10293
Gen:Variant.Ransom.Loki.10302
Gen:Variant.Ransom.Loki.1033