Site icon Back End News

Kaspersky reports Loki backdoor targets Russian companies

Earth World Computer Cybersecurity Cyber Security

Kaspersky researchers have discovered a new version of the Loki backdoor malware, which has been used in cyberattacks against at least 12 Russian companies across various sectors, including engineering and healthcare. 

According to Kaspersky, a cybersecurity solutions company, the malware, named Backdoor.Win64.MLoki, is based on the open-source Mythic post-exploitation framework.

Loki spreads through phishing emails containing malicious attachments. Once activated, attackers can control the compromised system, manage Windows access tokens, inject code into running processes, and transfer files to a command-and-control server.

“The growing use of open-source frameworks by attackers is concerning,” said Artem Ushkov, research developer at Kaspersky. “Loki exemplifies how these tools are being modified to avoid detection and attribution.”

The malware lacks traffic tunneling capabilities, so attackers use utilities like ngrok and gTunnel to penetrate private networks. In some cases, the gTunnel utility is modified to run in memory, making it harder to detect.

Although Kaspersky has not linked Loki to any specific threat group, their analysis shows that attackers customize each phishing email for its target.

Exit mobile version