Hoang, M. (2019, January 31). Malicious Activity Report: Elements of Lokibot Infostealer. Retrieved May 15, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareLokibot | Lokibot has obfuscated strings with base64 encoding. |
| T1027.002 Software Packing |
MalwareLokibot | Lokibot has used several packing methods for obfuscation. |
| T1055.012 Process Hollowing |
MalwareLokibot | Lokibot has used process hollowing to inject itself into legitimate Windows process. |
| T1071.001 Web Protocols |
MalwareLokibot | Lokibot has used HTTP for C2 communications. |
| T1555 Credentials from Password Stores |
MalwareLokibot | Lokibot has stolen credentials from multiple applications and data sources including Windows OS credentials, email clients, FTP, and SFTP clients. |
| T1555.003 Credentials from Web Browsers |
MalwareLokibot | Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers. |
| T1564.001 Hidden Files and Directories |
MalwareLokibot | Lokibot has the ability to copy itself to a hidden file and directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.