Skip to main content
Mallory
MalwareUsed by 2 actors

LodaRAT

LodaRAT is a remote access trojan/tool active since at least 2016 and written in AutoIt. It has been observed in multiple in-the-wild versions and used in both cyber-espionage and crimeware-style campaigns. Reported operators include the espionage-focused threat actor YoroTrooper, although Cisco Talos assessed LodaRAT is used by multiple distinct operators and not solely by the actor associated with its Android counterpart.

Observed delivery methods include earlier multi-stage phishing chains using malicious Microsoft Word documents that exploited CVE-2017-11882 and downloaded an MSI containing the compiled AutoIt script, as well as newer phishing emails carrying renamed RAR archives with a .rev extension that contain the compiled AutoIt binary and rely on user execution. Rapid7 also reported distribution via phishing, vulnerability exploitation, DonutLoader, and CobaltStrike.

Capabilities directly described in the source material include remote access functionality, screenshot capture, credential and cookie theft, and active C2-driven tasking. Cisco Talos reported a PowerShell keylogger in version 1.1.1 that is written to tmpwstz21.ps1 and executed on receipt of the C2 command MgPlugUp, with logs written to the temp directory using the current date as the filename. Talos also observed the C2 command Screen sending screenshots at regular intervals, and MpS8x generating a VBScript to display a custom message box. Version 1.1.7 was reported to focus on stealing passwords and cookies from browsers and to check Windows versions via the AutoIt macro @OSVERSION before copying itself to Temp or Startup locations and executing the copy. Rapid7 additionally reported theft of credentials and cookies from Microsoft Edge and Brave, persistence via registry modification or scheduled tasks, screen capture with hidden storage, microphone and webcam recording with exfiltration to C2, creation of new user accounts, disabling of Windows Firewall, and SMB-based lateral movement including attempts to connect to internal IPs over port 445.

Operationally, Talos observed direct threat-actor interaction with infected hosts, suggesting active monitoring and possible manual sandbox recognition from returned screenshots. Talos also reported use of legitimate tunneling or port-forwarding services such as ngrok.io and portmap.io for C2 anonymization. Mentioned infrastructure and indicators include the C2 URL http://roodan888tools[.]atwebpages[.]com/ng.txt, IPs 193[.]161[.]193[.]99 and 174[.]126[.]51[.]178, the dead stream reference live.mp3quran[.]net:9976 used by the QURAN command, the filename BYDVRI.vbs used by a single-instance VBScript in version 1.1.1, and tmpwstz21.ps1.

Targeting has varied by campaign. Talos linked LodaRAT use to YoroTrooper operations targeting government and energy-sector organizations in Azerbaijan, Tajikistan, Kyrgyzstan, other CIS countries, and some European entities. Rapid7 described a newer campaign as global and indiscriminate rather than regionally focused, with roughly 30% of VirusTotal samples reportedly uploaded from the United States.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Kasablanka

YoroTrooper has relied heavily on the use of primarily two commodity malware families, AveMaria/Warzone RAT and LodaRAT, especially in October and November 2022.

via talos intelligence blogblog.talosintelligence.com
YoroTrooper

YoroTrooper has relied heavily on the use of primarily two commodity malware families, AveMaria/Warzone RAT and LodaRAT, especially in October and November 2022.

via talos intelligence blogblog.talosintelligence.com
INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
domain●●●●●●●●●●●●View more in app3 years ago
ACTIVITY FEED

Recent activity

3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security online infoNews
Nov 15, 2024
LodaRAT Strikes Again: New Campaign Targets Global Victims with Updated Capabilities

LodaRAT is a remote access trojan active since 2016, used for information gathering, cyber-espionage, and data theft. The latest variant targets browser credentials, captures screens, records audio/video, creates user accounts, disables firewalls, and spreads laterally via SMB. It is distributed via phishing, vulnerability exploitation, and loaders like DonutLoader and CobaltStrike.

Read more
talos intelligence blogNews
Mar 14, 2023
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agency

RAT family used by YoroTrooper; Talos notes LodaRAT is attributed to (and likely developed by) the Kasablanka actor but appears used by multiple distinct operators/campaigns. YoroTrooper’s LodaRAT variants deviate from versions previously associated with Kasablanka and resemble versions seen in crimeware campaigns alongside RedLine and VenomRAT.

Read more
talos intelligence blogNews
Sep 29, 2020
LodaRAT Update: Alive and Well

Remote access trojan (AutoIt) observed in multiple in-the-wild versions. Recent variants dropped prior obfuscation, added/removed auxiliary scripts (hex-encoded PowerShell keylogger; VBScript single-instance enforcement), and include capabilities such as screenshot capture, interactive command execution from C2, persistence via copying to Temp/Startup depending on Windows version, and credential theft (passwords/cookies from browsers). C2 traffic observed via legitimate tunneling/port-forwarding services (ngrok.io, portmap.io), enabling anonymization and access to infected hosts.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.