HomeSecurityMalicious LokiBot trojan campaign disguises itself as a game launcher

Malicious LokiBot trojan campaign disguises itself as a game launcher

Malicious LokiBot trojan campaign disguises itself as a game launcher

Malicious hackers have launched a new campaign to distribute the powerful LokiBot trojan to their victims, disguising it as a game launcher.

The LokiBot trojan, first seen in 2015, remains very popular among cybercriminals as it creates a backdoor on infected Windows. It steals sensitive information from victims – including usernames, passwords, banking details and the contents of cryptocurrency wallets – through the use of a keylogger that monitors browser and desktop activity.

And now malicious actors are using a new LokiBot campaign to infect their victims, which they have disguised as a launcher from Epic Games, the developer behind the wildly popular online game Fortnite.

This newly discovered LokiBot campaign was analyzed by Trend Micro, who note that it uses an unusual installation routine to prevent detection by antivirus software.

As researchers report, the malware is distributed via phishing emails sent to potential targets.

Downloading and running the fake Epic Game launcher, which uses the company's logo to appear legitimate, begins the infection process. Initially, the malware downloads two separate files – a C# source code file and a .NET executable – to the machine's application data directory.

The C# source code is very confusing, containing sections of code that mean nothing but allow the LokiBot installer to bypass any security measures on the machine.

Once inside the system, the .NET file reads and conforms to the C# code, before decrypting it and executing LokiBot on the infected machine. This provides the attacker with the backdoor needed to steal information, monitor activity, install other malware, and perform other malicious actions on the device.

LokiBot continues to be a profitable malware, in part because early in its creation, its underlying code was leaked, giving cybercriminals the opportunity to develop their own versions of the malware.

In order to protect themselves from LokiBot attacks and other malicious applications, it is recommended that users only download software and attachments from trusted sources, and that organizations use security to ensure networks can detect potential threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS