Lokibot malware is a trojan family used to steal sensitive information, especially usernames, passwords, cryptocurrency wallets, and other credentials. It is commonly delivered through attachment, download, or execution-based techniques, then used to collect data and communicate with remote infrastructure for follow-on abuse.
What Lokibot Malware Is
Lokibot malware is a trojan family that steals sensitive information, especially usernames, passwords, cryptocurrency wallets, and other credentials. It typically enters through attachments, downloads, or execution-based lures, then uses the infected system to collect data and communicate with remote infrastructure for follow-on abuse.
How Lokibot Malware Works
Lokibot is best understood as information-stealing malware with a strong credential-exfiltration focus. Once executed, it harvests whatever secrets and account material it can reach on the host, then sends the results to attacker-controlled infrastructure so the captured data can be used, sold, or combined with other access paths.
That operating model makes the malware useful for more than a single account compromise. Stolen passwords, browser-stored sessions, wallet details, and saved tokens can let attackers pivot into email, cloud services, finance platforms, or other connected systems that trust the stolen access material.
Because Lokibot is delivered through ordinary user interaction, its early-stage success often depends on disguise, urgency, and execution. The malware itself is not complicated in concept, but it is effective because it turns a single endpoint compromise into a broader credential-loss event.
Common Abuse Patterns and Security Implications
Lokibot is commonly used as a first-stage infostealer, meaning its immediate purpose is to collect secrets rather than to destroy systems. In practice, that creates downstream risk when the attacker reuses the stolen material for account takeover, fraud, or access to higher-value services.
One useful way to think about the threat is that the malware turns endpoint compromise into identity compromise. Once credentials or session material are exposed, defenders may face password resets, token revocation, wallet migration, and investigation across multiple services rather than a single infected machine.
Defenders should also treat harvested data as a persistence enabler. If remote infrastructure receives fresh credential dumps repeatedly, the attacker can keep trying those credentials, refresh access, or resell the collection to other actors who will do the same.
For deeper reading on the credential-theft and follow-on abuse patterns that make infostealer activity dangerous, see CircleCI breach 2023 and Shai Hulud npm malware campaign.
Detection and Response Considerations
Detection usually starts with the endpoint, where unusual process launches, suspicious downloads, archive execution, credential-stealing behavior, or unexpected outbound connections can indicate infection. The network layer matters too, because exfiltration to remote command infrastructure often follows shortly after the initial execution.
Response should assume secret exposure until proven otherwise. That means resetting compromised credentials, invalidating active sessions, reviewing wallet or financial exposure where relevant, and checking for secondary access obtained with the stolen material.
Because Lokibot is a trojan family rather than a single fixed sample, signature-only thinking is brittle. The better defensive posture is to focus on the behavior chain, from delivery and execution to collection and exfiltration, then to the abuse of whatever secrets were exposed.
Practical control guidance is reinforced by CIS Controls v8, along with broader monitoring and credential-protection measures such as NIST SP 800-53 Rev 5 Security and Privacy Controls and MITRE ATT&CK Enterprise Matrix.
Risk and Threat Considerations
Lokibot is risky because a single successful infection can expose many valuable secrets at once, especially when users reuse passwords or store credentials and session material on the endpoint. The real danger is often not the malware process itself, but the broader account compromise that follows.
Failure mechanism: The malware captures credentials, wallet data, or active session material and sends it to attacker infrastructure, where the stolen access can be reused before defenders detect the loss.
Impact: Organisations and individuals can face account takeover, financial theft, secondary breaches, and repeated abuse of any services that trusted the stolen secrets.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Lokibot steals credentials and sessions that account controls must protect. |
| Recommendation — Harden account lifecycle controls and revoke any credentials exposed by an infostealer. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Lokibot targets passwords, tokens, and other authenticators used for access. |
| Recommendation — Rotate and protect authenticators, then invalidate any that were exposed. | ||
| MITRE ATT&CK | T1555 — Credentials from Password Stores | Lokibot commonly steals stored credentials and browser-based secret material. |
| Recommendation — Hunt for password-store access and credential-dumping behavior in endpoint telemetry. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Lokibot’s core abuse path is the theft and exfiltration of secrets. |
| NHI-07 — Long-Lived Secrets | The malware benefits when stolen secrets remain valid for extended periods. | |
| Recommendation — Reduce secret exposure on endpoints and remove any leaked material immediately. Shorten secret lifetimes and rotate anything that could outlive a compromise. | ||
Practitioner Guidance
What to watch for: Treat unexpected credential theft on a workstation as a containment event, not just an endpoint cleanup task. The key judgement is whether the host exposed material that can still be used elsewhere, including passwords, browser sessions, API keys, or wallet access.
Practitioner takeaway: With infostealers like Lokibot, the priority is not only removing the malware, but also closing every access path the malware may have copied.
Related resources from NHI Mgmt Group
- What happens when Lokibot-style malware is allowed to execute before security teams detect it?
- What makes Shai Hulud 2.0 different from a normal npm malware event?
- Why can a compromise of Intune or similar tools cause business disruption without malware?
- Why are identity-driven attacks harder to detect than malware-based attacks?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org