ATT&CKReferencesInfoblox Lokibot January 2019

Infoblox Lokibot January 2019

Hoang, M. (2019, January 31). Malicious Activity Report: Elements of Lokibot Infostealer. Retrieved May 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareLokibot

Lokibot has obfuscated strings with base64 encoding.

T1027.002
Software Packing
MalwareLokibot

Lokibot has used several packing methods for obfuscation.

T1055.012
Process Hollowing
MalwareLokibot

Lokibot has used process hollowing to inject itself into legitimate Windows process.

T1071.001
Web Protocols
MalwareLokibot

Lokibot has used HTTP for C2 communications.

T1555
Credentials from Password Stores
MalwareLokibot

Lokibot has stolen credentials from multiple applications and data sources including Windows OS credentials, email clients, FTP, and SFTP clients.

T1555.003
Credentials from Web Browsers
MalwareLokibot

Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers.

T1564.001
Hidden Files and Directories
MalwareLokibot

Lokibot has the ability to copy itself to a hidden file and directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.