Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LokiBot Campaign Revives with Advanced Evasion Techniques

LokiBot Campaign Revives with Advanced Evasion Techniques

Posted on June 25, 2026 By CWS

The notorious credential-stealing malware LokiBot has made a comeback in a sophisticated multi-stage operation aimed at extracting sensitive information from various applications. This campaign, identified for its clever mix of old and new tactics, uses a JScript email attachment to initiate a stealthy sequence of events, ultimately leading to the exfiltration of confidential data from the victim’s device.

LokiBot’s Evolving Tactics

Initially advertised on underground forums in 2015, LokiBot’s source code leak in 2018 led to the emergence of numerous variants, extending its capabilities to Android devices and enabling functions like keylogging and remote access. The current campaign underscores the malware’s evolution, incorporating both tried-and-true methods and novel evasion strategies to bypass security systems.

Security researchers from LevelBlue have highlighted the meticulous planning behind each stage of this campaign, designed to minimize detection and erase traces if necessary. They reported to Cyber Security News that the malware is predominantly distributed through malicious email attachments, a method that continues to be prevalent due to its simplicity and effectiveness.

Technical Breakdown of the Attack

The attack commences when a recipient opens a phishing email containing a JScript file. Once executed, the script leverages the Windows Script Host to run, employing obfuscation techniques to hinder analysis. The JScript then unpacks a Base64-encoded PowerShell script, executing it to further the infection process.

This PowerShell stage decrypts a .NET assembly with a hard-coded XOR key, which is then loaded directly into memory. The assembly, protected by the ConfuserEx obfuscator, functions as an injector, deploying the LokiBot payload into a legitimate Windows process, thus evading detection.

Implications and Preventative Measures

LokiBot poses a severe threat by capturing credentials from over a hundred applications, including web browsers, cryptocurrency wallets, and email clients. The stolen data is compressed and sent to a command-and-control server, risking account takeovers and data breaches.

To counteract these threats, organizations should implement robust security measures, such as blocking script-based email attachments, monitoring unusual activity around processes like aspnet_compiler.exe, and utilizing behavior-based endpoint protection to detect malicious patterns. Regular updates and staff awareness training can further mitigate these risks.

In conclusion, the resurgence of LokiBot in this advanced campaign highlights the persistent and evolving nature of cyber threats. Staying informed and vigilant is crucial for organizations to safeguard against such sophisticated malware incursions. Continuous monitoring and adapting to emerging tactics will be essential in the fight against cybercrime.

Cyber Security News Tags:advanced evasion, command-and-control, credential theft, cyber attack, Cybersecurity, data breach, email phishing, JScript, LokiBot, Malware, network security, PowerShell, process injection, security measures, threat analysis

Post navigation

Previous Post: Runlayer Secures $30M in Series A Funding Boost
Next Post: Lantronix Device Vulnerability Exploited in OT Attacks

Related Posts

Identity Theft Surges as Criminals Deploy Advanced Tactics to Steal Personal Data Identity Theft Surges as Criminals Deploy Advanced Tactics to Steal Personal Data Cyber Security News
Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack Cyber Security News
Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack Cyber Security News
Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks Multiple GitLab Vulnerabilities Enables 2FA Bypass and DoS Attacks Cyber Security News
New Ghost-tapping Attacks Steal Customers’ Cards Linked to Services Like Apple Pay and Google Pay New Ghost-tapping Attacks Steal Customers’ Cards Linked to Services Like Apple Pay and Google Pay Cyber Security News
New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials New QR Code Attack Via PDFs Evades Detection Systems and Harvest Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Popular Chrome Ad Blocker Raises Security Concerns
  • Malicious npm Packages Compromise Developer Credentials
  • Lantronix Device Vulnerability Exploited in OT Attacks
  • LokiBot Campaign Revives with Advanced Evasion Techniques
  • Runlayer Secures $30M in Series A Funding Boost

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Popular Chrome Ad Blocker Raises Security Concerns
  • Malicious npm Packages Compromise Developer Credentials
  • Lantronix Device Vulnerability Exploited in OT Attacks
  • LokiBot Campaign Revives with Advanced Evasion Techniques
  • Runlayer Secures $30M in Series A Funding Boost

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark