216.73.216.6

Loki: a new private agent for the popular Mythic framework

· Published 09/09/2024 09:22 · Modified 09/09/2024 09:52

Export JSON

Essential information

Published
09/09/2024 09:22
Modified
09/09/2024 09:52
Tags
2024-09-09 agent backdoor hellokitty loader malware mythic
Related entities
7 observables, 8 techniques (mitre), 1 malware, 3 others

Description

Kaspersky researchers discovered a previously unknown Loki , utilized in a series of targeted attacks. Analysis revealed that Loki is a private version of an compatible with the open-source framework. The employs techniques like memory encryption, indirect system API calls, and API function hashing to impede analysis. It comprises a and a DLL, with the latter implementing core functionalities. The gathers system information and communicates with the command-and-control server to obtain the payload DLL. Loki inherits commands from various agents and supports capabilities like file transfers, code injection, and token management. Attackers likely distribute the via email, targeting Russian companies across multiple industries.

External references