Security News Loki Bot Attacks Target Corporate Mailboxes

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,333
Loki Bot’s operators have been targeting corporate mailboxes with their spam messages, Kaspersky Lab reports.

The emails employ various lures to trick potential victims into opening malicious attachments that would deploy the Loki Bot stealer onto the target machines. The messages masquerade as notifications from other companies, or as orders and offers.

As part of the campaign, cybercriminals have been targeting corporate mailboxes that can be obtained from public sources or which are listed on the targeted companies’ websites, Kaspersky discovered.

The spam messages would attempt to deliver the malicious payload via an attached ISO file. The extension is associated with copies of optical discs that can be mounted to access their content. Modern operating systems can mount ISO files directly, but dedicated software that can handle the extension also exists.

ISO files represent complete images of optical discs, and cybercriminals are now abusing them as containers for delivering their malicious applications, it seems. Such occurrences, however, are rare, Kaspersky says.

As part of the recent campaign, the ISO files contained the Loki Bot malware, an information-stealing Trojan designed to harvest usernames and passwords from the victim machines, along with other user data.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top