Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
Luca Stealer
Technical ID: win.luca_stealer
MALWARE
According to PCRisk, The Luca stealer can extract a variety of information from compromised machines. It targets data related to the following: operating system, device name, CPUs, desktop environment, network interface, user account name, preferred system language, running processes, etc.
This malicious program can steal information from over thirty Chromium-based browsers. From these applications, Luca can obtain Internet cookies, account log-in credentials (usernames/passwords), and credit card numbers. Additionally, the stealer can extract data from password manager and cryptowallet browser extensions compatible with over twenty browsers.
This malware also targets various messaging applications like Telegram, Discord, ICQ, Skype, Element, etc. It likewise aims to acquire information from gaming-related software such as Steam and Uplay (Ubisoft Connect). Furthermore, some versions of Luca can take screenshots and download the files stored on victims' devices.
LuaDream
Technical ID: win.luadream
MALWARE
Malware family identifying win.luadream. Origin and technical characteristics tracked via Malpedia.
Also known as: DreamLand
Lu0Bot
Technical ID: win.lu0bot
MALWARE
According to PCrisk, Lu0bot es un software malicioso. El malware es ligero, por lo que su uso de los recursos del sistema es bajo. Esto complica la detección de Lu0bot, ya que no causa síntomas significativos, como una grave disminución del rendimiento del sistema.
El programa malicioso funciona como un recolector de telemetría.
lsassDumper
Technical ID: win.lsassdumper
MALWARE
This in Go written malware is lsass process memory dumper, which was custom developed by threat actors according to Security Joes. It has the capability to automatically exfiltrate the results to the free file transfer service "transfer.sh".
MALWARE
LPEClient is an HTTP(S) downloader that expects two command line parameters: an encrypted string containing two URLs (a primary and a secondary C&C server), and the path on the victim's file system to store the downloaded payload.
It sends detailed information about the victim's environment, like computer name, type and number of processors, computer manufacturer, product name, major and minor Windows versions, architecture, memory information, installed security software and the version of the ntoskrnl.exe from its version-information resource.
LPEClient uses specific 32-bit values to represent its execution state (0x59863F09 when connecting via the WinHTTP interface, 0xA9348B57 via WinINet), or the nature of HTTP requests to the C&C servers (0xF07D6B34 when sending system information, 0xEF8C0D51 when requesting a DLL payload, 0xCB790A25 when reporting the successful loading of the DLL, 0xD7B20A96 when reporting the state of the the DLL execution). As the final step, malware looks for the export CloseEnv and executes it.
Also known as: LPEClientTea
MALWARE
Malware family identifying win.lowzero. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.lowkey. Origin and technical characteristics tracked via Malpedia.
Also known as: PortReuse
MALWARE
LOWBALL, uses the legitimate Dropbox cloud-storage
service to act as the CnC server. It uses the Dropbox API with a hardcoded bearer access token and has the ability to download, upload, and execute files. The communication occurs via HTTPS over port 443.
LoupeLoader
Technical ID: win.loupeloader
MALWARE
Malware family identifying win.loupeloader. Origin and technical characteristics tracked via Malpedia.
Loup
Technical ID: win.loup
MALWARE
Frank Boldewin describes Loup as a small cli-tool to cash out NCR devices (ATM).
Lorenz
Technical ID: win.lorenz
MALWAREfinancialhigh
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
L0rdix
Technical ID: win.lordix
MALWARE
L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018. Out of the box, L0rdix supports eight commands, although custom commands can be defined and added. These include:
Download and execute
Update
Open page (visible)
Open page (invisible)
Cmd
Kill process
Upload file
HTTP Flood
L0rdix can extract credentials from common web browsers and steal data from crypto wallets and a target's clipboard. Optionally, L0rdix can deploy a cryptominer (XMRig) to its bots.
Also known as: lordix
MALWARE
Malware family identifying win.lookback. Origin and technical characteristics tracked via Malpedia.
LooCipher
Technical ID: win.loocipher
MALWAREfinancialhigh
LooCipher is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank to the term “Cipher”) and to the popular mythological figure, Lucifer. Despite its evocative nickname, the functionalities of this malware are pretty straight forward, not very different from those belonging to many other ransomware families.
Updated: 2023-09-11
View profile →looChiper
Technical ID: win.loochiper
MALWAREfinancialhigh
LooChiper is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank to the term “Cipher”) and to the popular mythological figure, Lucifer. Despite its evocative nickname, the functionalities of this malware are pretty straight forward, not very different from those belonging to many other ransomware families.
Updated: 2023-09-11
View profile →MALWARE
The primary function of LONGWATCH is a keylogger that outputs keystrokes to a log.txt file in the Windows temp folder.
LOLSnif
Technical ID: win.lolsnif
MALWARE
Malware family identifying win.lolsnif. Origin and technical characteristics tracked via Malpedia.
Lokorrito
Technical ID: win.lokorrito
MALWAREfinancialhigh
According to ESET, this is a banking trojan that was active mainly in Mexico until the beginning of 2020, with builds for Brazil, Chile, and Colombia also having been identified.
MALWARE
"Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMe
Loki-Bot employs function hashing to obfuscate the libraries utilized. While not all functions are hashed, a vast majority of them are.
Loki-Bot accepts a single argument/switch of ‘-u’ that simply delays execution (sleeps) for 10 seconds. This is used when Loki-Bot is upgrading itself.
The Mutex generated is the result of MD5 hashing the Machine GUID and trimming to 24-characters. For example: “B7E1C2CC98066B250DDB2123“.
Loki-Bot creates a hidden folder within the %APPDATA% directory whose name is supplied by the 8th thru 13th characters of the Mutex. For example: “%APPDATA%\ C98066\”.
There can be four files within the hidden %APPDATA% directory at any given time: “.exe,” “.lck,” “.hdb” and “.kdb.” They will be named after characters 13 thru 18 of the Mutex. For example: “6B250D.” Below is the explanation of their purpose:
FILE EXTENSION FILE DESCRIPTION
.exe A copy of the malware that will execute every time the user account is logged into
.lck A lock file created when either decrypting Windows Credentials or Keylogging to prevent resource conflicts
.hdb A database of hashes for data that has already been exfiltrated to the C2 server
.kdb A database of keylogger data that has yet to be sent to the C2 server
If the user is privileged, Loki-Bot sets up persistence within the registry under HKEY_LOCAL_MACHINE. If not, it sets up persistence under HKEY_CURRENT_USER.
The first packet transmitted by Loki-Bot contains application data.
The second packet transmitted by Loki-Bot contains decrypted Windows credentials.
The third packet transmitted by Loki-Bot is the malware requesting C2 commands from the C2 server. By default, Loki-Bot will send this request out every 10 minutes after the initial packet it sent.
Communications to the C2 server from the compromised host contain information about the user and system including the username, hostname, domain, screen resolution, privilege level, system architecture, and Operating System.
The first WORD of the HTTP Payload represents the Loki-Bot version.
The second WORD of the HTTP Payload is the Payload Type. Below is the table of identified payload types:
BYTE PAYLOAD TYPE
0x26 Stolen Cryptocurrency Wallet
0x27 Stolen Application Data
0x28 Get C2 Commands from C2 Server
0x29 Stolen File
0x2A POS (Point of Sale?)
0x2B Keylogger Data
0x2C Screenshot
The 11th byte of the HTTP Payload begins the Binary ID. This might be useful in tracking campaigns or specific threat actors. This value value is typically “ckav.ru”. If you come across a Binary ID that is different from this, take note!
Loki-Bot encrypts both the URL and the registry key used for persistence using Triple DES encryption.
The Content-Key HTTP Header value is the result of hashing the HTTP Header values that precede it. This is likely used as a protection against researchers who wish to poke and prod at Loki-Bot’s C2 infrastructure.
Loki-Bot can accept the following instructions from the C2 Server:
BYTE INSTRUCTION DESCRIPTION
0x00 Download EXE & Execute
0x01 Download DLL & Load #1
0x02 Download DLL & Load #2
0x08 Delete HDB File
0x09 Start Keylogger
0x0A Mine & Steal Data
0x0E Exit Loki-Bot
0x0F Upgrade Loki-Bot
0x10 Change C2 Polling Frequency
0x11 Delete Executables & Exit
Suricata Signatures
RULE SID RULE NAME
2024311 ET TROJAN Loki Bot Cryptocurrency Wallet Exfiltration Detected
2024312 ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M1
2024313 ET TROJAN Loki Bot Request for C2 Commands Detected M1
2024314 ET TROJAN Loki Bot File Exfiltration Detected
2024315 ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M1
2024316 ET TROJAN Loki Bot Screenshot Exfiltration Detected
2024317 ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M2
2024318 ET TROJAN Loki Bot Request for C2 Commands Detected M2
2024319 ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M2
Also known as: Burkina • Loki • LokiBot • LokiPWS
LokiLocker
Technical ID: win.lokilocker
MALWAREfinancialhigh
LokiLocker is a .Net ransomware, which was seen first in August 2021. This malware is protected with NETGuard (modified ConfuserEX) using the additional KoiVM virtualization plugin.
The victims were observed ti be scattered around the world, with main concentation in Estern Europe and Asia (BlackBerry).
MALWARE
Malware family identifying win.lojax. Origin and technical characteristics tracked via Malpedia.
Logtu
Technical ID: win.logtu
MALWARE
Malware family identifying win.logtu. Origin and technical characteristics tracked via Malpedia.
LogPOS
Technical ID: win.logpos
MALWARE
Malware family identifying win.logpos. Origin and technical characteristics tracked via Malpedia.
Logedrut
Technical ID: win.logedrut
MALWARE
Malware family identifying win.logedrut. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.lodeinfo. Origin and technical characteristics tracked via Malpedia.
Loda
Technical ID: win.loda
MALWARE
Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims. Proofpoint first observed Loda in September of 2016 and it has since grown in popularity. The name Loda is derived from a directory to which the malware author chose to write keylogger logs. It should be noted that some antivirus products currently detect Loda as “Trojan.Nymeria”, although the connection is not well-documented.
Also known as: LodaRAT • Nymeria
LockPOS
Technical ID: win.lock_pos
MALWARE
Malware family identifying win.lock_pos. Origin and technical characteristics tracked via Malpedia.
Locky Loader
Technical ID: win.locky_loader
MALWARE
For the lack of a better name, this is a VBS-based loader that was used in beginning of 2018 to deliver win.locky.
Updated: 2018-01-11
View profile →Locky (Decryptor)
Technical ID: win.locky_decryptor
MALWARE
Malware family identifying win.locky_decryptor. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →MALWAREfinancialhigh
Locky is a high profile ransomware family that first appeared in early 2016 and was observed being active until end of 2017. It encrypts files on the victim system and asks for ransom in order to have back original files. In its first version it added a .locky extension to the encrypted files, and in recent versions it added the .lukitus extension. The ransom amount is defined in BTC and depends on the actor.
LockFile
Technical ID: win.lockfile
MALWAREfinancialhigh
A ransomware first observed in July 2021.
MALWAREfinancialhigh
According to Trend Micro, LockerGoga is a ransomware that has been used in multiple attacks, most notably against Altran Technologies and Norsk Hydro. It encrypts a range of documents and source code files but certain versions had little to no whitelist that would protect import system files such as the Windows Boot Manager.
LockBit
Technical ID: win.lockbit
MALWARE
Malware family identifying win.lockbit. Origin and technical characteristics tracked via Malpedia.
Also known as: ABCD Ransomware
LOBSHOT
Technical ID: win.lobshot
MALWAREfinancialhigh
According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to access a victim's computer without being noticed. The hVNC component is effective in evading fraud detection systems. Also, LOBSHOT is being used to carry out financial crimes through the use of banking trojan and information-stealing functionalities.
LiteHTTP
Technical ID: win.litehttp
MALWARE
According to AlienVault, LiteHTTP bot is a new HTTP bot programmed in C#. The bot has the ability to collect system information, download and execute programs, and update and kill other bots present on the system.
The source is on GitHub: https://github.com/zettabithf/LiteHTTP
MALWARE
According to CarbonBlack, LiteDuke is a third stage backdoor. It appears to use the same dropper as PolyglotDuke. Its payload makes use of an AES encrypted SQLite database to store its configuration. LiteDuke supports a large number of individual commands including host information retrieval, file upload and download, and the ability to execute other code. LiteDuke C2 servers appear to be compromised servers, and the malware communicates with them using normal HTTP requests. It attempts to use a realistic User-Agent string to blend in better with normal HTTP traffic.
ESET have dubbed it LiteDuke because it uses SQLite to store information such as its configuration.
MALWARE
Malware family identifying win.listrix. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.liontail. Origin and technical characteristics tracked via Malpedia.
LinseningSvr
Technical ID: win.linseningsvr
MALWARE
Malware family identifying win.linseningsvr. Origin and technical characteristics tracked via Malpedia.
Limitail
Technical ID: win.limitail
MALWARE
Malware family identifying win.limitail. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →