s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.loki

📛 Threat Title

Malware family: Loki

Category: Loki First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.loki`. Printable name: Loki.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.loki VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.loki

IOC database

Type
domain
Value
apk.loki
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.loki

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.loki

References (1)

Remediations (10)

  • web:any.run

    LokiBot, also known as Loki -bot or Loki bot, is an information stealer malware that collects data from the most widely used web browsers, FTP, email clients, and over a hundred software tools installed on the infected machine. Follow live malware statistics of this infostealer and get new reports, samples, IOCs, etc

  • web:attack.mitre.org

    Lokibot is a widely distributed information stealer that was first reported in 2015. It is designed to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. Lokibot can also create a backdoor into infected systems to allow an attacker to install additional payloads. [1] [2] [3]

  • web:cybersecuritynews.com

    The threat actor group known as Arcane Werewolf, also tracked as Mythic Likho, has refreshed its attack capabilities by deploying a new version of its custom malware called Loki 2.1. During October and November 2025, researchers observed this group launching campaigns specifically targeting Russian manufacturing companies. The group continues to refine its tactics, showing a sustained interest ...

  • web:github.com

    This repository contains a narrated malware analysis presentation focused on LokiBot, a widely distributed information stealer and remote access trojan. The investigation includes static analysis, behavioral trait identification, and MITRE ATT&CK mapping.

  • web:hunt.io

    LokiBot—also known as Loki PWS and Loki -bot—is a Trojan malware designed to steal sensitive information, including usernames, passwords, and cryptocurrency wallet credentials. This malware operates by employing a keylogger to monitor browser and desktop activity. Additionally, LokiBot creates a backdoor into infected systems, enabling attackers to deploy additional payloads. The malware ...

  • web:malpedia.caad.fkie.fraunhofer.de

    The first packet transmitted by Loki -Bot contains application data. The second packet transmitted by Loki -Bot contains decrypted Windows credentials. The third packet transmitted by Loki -Bot is the malware requesting C2 commands from the C2 server. By default, Loki -Bot will send this request out every 10 minutes after the initial packet it sent.

  • web:success.trendmicro.com

    Loki is an info-stealer malware that was first detected on February 2016. This malware first targeted Android systems and its capabilities include stealing credentials, disabling notifications, intercepting communications and data ex filtration.

  • web:www.cisa.gov

    LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials.

  • web:www.cisecurity.org

    LokiBot—also known as Lokibot, Loki PWS, and Loki -bot—employs Trojan malware to steal sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials.

  • web:www.hhs.gov

    Technical Details LokiBot, also known as Lokibot, Loki PWS, and Loki -bot, employs trojan malware to steal sensitive informaiton such as usernames, passwords, cryptocurrency wallets, and other credentials. According to one security researcher, in two-thirds of attack attempts, the LokiBot malware arrives in the form of an email attachment.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.