CISA issued a security alert yesterday, aiming to inform federal agencies and the private sector about a significant increase in the use of LokiBot malware by hackerssince last July.
Specifically, CISA said that its internal security platform (the EINSTEIN intrusion detection system ) detected a series of malicious activities, behind which the LokiBot malware is hidden. The sharp increase in LokiBot activity since July was confirmed to ZDNet by the Malwarebytes Threat Intelligence team .

This is particularly concerning, given that LokiBot is one of the most dangerous and widespread malware strains currently present in the threat landscape. The LokiBot trojan, also known as Loki or Loki PWS, is a so-called infostealer.
In terms of its action, LokiBot infects computers and then uses its built-in capabilities to search for locally installed applications and steal credentials from their internal databases . In addition, LokiBot can target email clients, browsers, FTP applications , and cryptocurrency wallets.

However, the malware is more than just an infostealer. Over time, LokiBot has evolved and now also comes with a real-time key-logging component to record keystrokes and steal passwords for accounts that are not always stored in the browser's internal database, and a desktop screenshot utility to capture documents after they are opened on the victim's computer. In addition, LokiBot also acts as a backdoor, allowing hackers to execute other pieces of malware on infected hosts and potentially stage attacks.
The malware first appeared in the mid-2010s, when it first appeared for sale on hacking forums. Since then, it has been pirated and widely distributed for free for years. It is one of the most popular password stealers today. Many hacking groups currently distribute the malware during their attacks, using a variety of techniques – from spam emails to cracked installers and boobytrapped torrent files.

SpamHaus ranked LokiBot as the malware with the most active command-and-control servers in 2019. In the same ranking, LokiBot is currently second in the first half of 2020. LokiBot also ranks third in AnyRun's all-time ranking of the most analyzed malware strains in the malware sandboxing service.
Credentials stolen by hackers via LokiBot usually end up on underground marketplaces like Genesis, where LokiBot is the second most popular type of malware traded.
The advisory published yesterday by CISA regarding LokiBot includes detection and mitigation tips to address malware attacks and infections.
Finally, it's worth noting that LokiBot should not be confused with a similar, now-defunct, Android trojan.
