Skip to content

LodaRAT

LodaRAT is a long-running remote access trojan and information-stealing malware family, active since at least 2016–2017, primarily associated with Windows and later expanded to Android through the related Loda4Android variant.

Profile source: Mallory opens in a new tab

LodaRAT

Family profile

LodaRAT is a long-running remote access trojan and information-stealing malware family, active since at least 2016–2017, primarily associated with Windows and later expanded to Android through the related Loda4Android variant. The Windows malware is written in AutoIt and has been used for remote system control, surveillance, credential theft, and broader espionage-oriented collection. Documented capabilities include screenshot capture, keystroke logging, audio recording, browser password and cookie theft, command execution, and persistence. More recent reporting also attributes to some variants the ability to disable host defenses, create user accounts, enable remote desktop access, and attempt lateral movement over SMB. Android variants add mobile surveillance and collection functions such as location tracking, ambient audio recording, photo and screenshot capture, SMS, call log, and contact theft, as well as command execution and phishing functionality.

LodaRAT has been delivered through multiple infection chains over time. Observed Windows delivery methods include phishing emails carrying malicious Office documents, exploit-based chains using CVE-2017-0199 and CVE-2017-11882, compressed archives containing executable payloads, and lure websites serving password-protected archives. Campaigns have also used fake or impersonating websites themed around government, telecom, finance, political, and public-service subjects to target victims. Newer distribution has included renamed RAR archives requiring user execution, and some reporting links delivery to additional tooling such as DonutLoader and Cobalt Strike.

Operational use of LodaRAT spans both commodity cybercrime and targeted espionage. It has been deployed by TA558 in phishing campaigns affecting Latin America and other regions, used by YoroTrooper in espionage activity targeting government and energy organizations in CIS countries, and linked by Cisco Talos to a cluster it tracks as Kasablanca in campaigns targeting Bangladesh. Kasablanca-linked activity has been assessed as information-gathering focused and possibly consistent with cyber-mercenary or hacker-for-hire tradecraft, although that characterization is not conclusive. Targeting associated with LodaRAT has included hospitality, tourism, finance, government, energy, education, IT, pharmaceuticals, transportation, banks, VoIP vendors, diplomatic entities, and other organizations.

The malware’s command-and-control tradecraft has evolved over time and has included abuse of legitimate tunneling or port-forwarding services to obscure infrastructure. Multiple versions have been observed in parallel, with differing feature sets and code quality, suggesting either active development, reuse by multiple operators, or both. Despite these variations, LodaRAT remains best characterized as a versatile RAT used for remote access, surveillance, credential theft, and post-compromise collection across Windows and Android environments.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Spoofing

Reported operators

Threat actors

4 named in public reporting
TA558

Once an attack succeeds, TA558 deploys multiple types of malware on victim machines — including AsyncRAT, LodaRAT, RevengeRAT, XWorm, and AgentTesla — for remote computer control and information theft.

Kasablanka

LodaRAT, or Loda, is information gathering malware. It has the ability to take screenshots of infected machines, record keystrokes and sound and allows its operators to send commands to the machine.

Kasablanca

The developers of LodaRAT have added Android as a targeted platform. A new iteration of LodaRAT for Windows has been identified with improved sound recording capabilities.

YoroTrooper

YoroTrooper has relied heavily on the use of primarily two commodity malware families, AveMaria/Warzone RAT and LodaRAT, especially in October and November 2022.

Exploited software

Vulnerabilities linked to LodaRAT

2 CVEs

MITRE ATT&CK

LodaRAT in ATT&CK

29 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.