TF-MAL-apk.loki
📛 Threat Title
Malware family: Loki
Description
ThreatFox malware family `apk.loki`. Printable name: Loki.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.loki
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.loki
IOC database
- Type
- domain
- Value
apk.loki- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.loki
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.loki
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
LokiBot, also known as Loki -bot or Loki bot, is an information stealer malware that collects data from the most widely used web browsers, FTP, email clients, and over a hundred software tools installed on the infected machine. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc
-
web:attack.mitre.org
Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads. [1] [2] [3]
-
web:cybersecuritynews.com
The threat actor group known as Arcane Werewolf, also tracked as Mythic Likho, has refreshed its attack capabilities by deploying a new version of its custom malware called Loki 2.1. During October and November 2025, researchers observed this group launching campaigns specifically targeting Russian manufacturing companies. The group continues to refine its tactics, showing a sustained interest ...
-
web:github.com
This repository contains a narrated malware analysis presentation focused on LokiBot, a widely distributed information stealer and remote access trojan. The investigation includes static analysis, behavioral trait identification, and MITRE ATT&CK mapping.
-
web:hunt.io
LokiBot—also known as Loki PWS and Loki -bot—is a Trojan malware designed to steal sensitive information, including usernames, passwords, and cryptocurrency wallet credentials. This malware operates by employing a keylogger to monitor browser and desktop activity. Additionally, LokiBot creates a backdoor into infected systems, enabling attackers to deploy additional payloads. The malware ...
-
web:malpedia.caad.fkie.fraunhofer.de
The first packet transmitted by Loki -Bot contains application data. The second packet transmitted by Loki -Bot contains decrypted Windows credentials. The third packet transmitted by Loki -Bot is the malware requesting C2 commands from the C2 server. By default, Loki -Bot will send this request out every 10 minutes after the initial packet it sent.
-
web:success.trendmicro.com
Loki is an info-stealer malware that was first detected on February 2016. This malware first targeted Android systems and its capabilities include stealing credentials, disabling notifications, intercepting communications and data ex filtration.
-
web:www.cisa.gov
LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials.
-
web:www.cisecurity.org
LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials.
-
web:www.hhs.gov
Technical Details LokiBot, also known as Lokibot, Loki PWS, and Loki -bot, employs trojan malware to steal sensitive informaiton such as usernames, passwords, cryptocurrency wallets, and other credentials. According to one security researcher, in two-thirds of attack attempts, the LokiBot malware arrives in the form of an email attachment.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.