LoFiSe

S1101

Malware.View on attack.mitre.org

About this malware

LoFiSe has been used by ToddyCat since at least 2023 to identify and collect files of interest on targeted systems.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1005
Data from Local System

LoFiSe can collect files of interest from targeted systems.

T1074.001
Local Data Staging

LoFiSe can save files to be evaluated for further exfiltration in the `C:\Programdata\Microsoft\` and `C:\windows\temp\` folders.

T1083
File and Directory Discovery

LoFiSe can monitor the file system to identify files less than 6.4 MB in size with file extensions including .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .odt, .ods, .odp, .eml, and .msg.

T1119
Automated Collection

LoFiSe can collect all the files from the working directory every three hours and place them into a password-protected archive for further exfiltration.

T1560
Archive Collected Data

LoFiSe can collect files into password-protected ZIP-archives for exfiltration.

T1574.001
DLL

LoFiSe has been executed as a file named DsNcDiag.dll through side-loading.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky ToddyCat Check Logs October 2023 Open source
    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.