Netskope Threat Labs

Lokibot

ATP Sandbox Adv. HeuristicsNetskope IPS

Lokibot (a.k.a. Loki) is an information stealer and keylogger that targets credentials stored in browsers, email clients, FTP programs, and other applications, with variants that also run on Android. Sold cheaply and rebranded many times, it became one of the most widely distributed commodity stealers of its era. Its campaigns rely on phishing, cracked software, and loaders, and stolen data flows to panels that operators use or resell.

First seen
March 2022
Last seen
October 2026
LokiBot

28 techniques across 10 tactics.

TA0001 Initial Access

TA0002 Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0006 Credential Access

  • T1555Credentials from Password Stores

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
Android.Ransomware.LokiBot
ByteCode-MSIL.Infostealer.LokiBot
ByteCode-MSIL.Trojan.LokiBot
Document-Office.Downloader.Lokibot
Document-Word.Downloader.Lokibot
Email-MIME.Trojan.LokiBot
Email-MSG.Infostealer.LokiBot
Script-AutoIt.Infostealer.LokiBot
Script-WScript.Trojan.LokiBot
Win32.Infostealer.LokiBot