Lokibot

Category: infostealer · Aliases: None known · Sample count (EMBER 2018): 55 · Enrichment: category-templated · Updated: 2026-05-27

Overview

Lokibot is an information-stealer family with 55 samples in ember 2018 that harvests credentials, cookies, autofill data, cryptocurrency wallets, and application data from infected systems. info-stealers are commonly delivered alongside ransomware as a precursor exfiltration step.

Frequently Asked Questions

What is Lokibot malware?

Lokibot is a member of the infostealer category in the EMBER 2018 malware corpus. Like other infostealer samples it shares the behaviors typical of that class. Because precise family-specific reporting on Lokibot is limited, this catalog only describes it at the category level rather than fabricating unverified details.

What should I do if Lokibot is detected on my system?

Do not attempt manual removal. Infostealer samples often establish persistence and may be part of a larger compromise. Isolate the affected system from the network and contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/lokibot.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.