Unraveling LokiBot: A Threat Actor’s Playbook in Credential Theft and Lateral Movement
James Calloway — Threat Hunter Key TakeawaysLokiBot leverages both phishing and exploit-based initial access methods to deploy its payloads.Persistent mechanisms include registry modifications and scheduled tasks, aiding long-term stealth.The tool employs complex C2 communication patterns…