ATT&CKReferencesFSecure Lokibot November 2019

FSecure Lokibot November 2019

Kazem, M. (2019, November 25). Trojan:W32/Lokibot. Retrieved May 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLokibot

Lokibot has the ability to discover the domain name of the infected host.

T1033
System Owner/User Discovery
MalwareLokibot

Lokibot has the ability to discover the username on the infected host.

T1041
Exfiltration Over C2 Channel
MalwareLokibot

Lokibot has the ability to initiate contact with command and control (C2) to exfiltrate stolen data.

T1056.001
Keylogging
MalwareLokibot

Lokibot has the ability to capture input on the compromised host via keylogging.

T1082
System Information Discovery
MalwareLokibot

Lokibot has the ability to discover the computer name and Windows product name/version.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.