Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:45:31 UTC Home > List all groups > List all tools > List all groups using tool LokiBot Tool: LokiBot Names LokiBot Loki LokiPWS Loki.Rat ForeIT Category Malware Type Banking trojan, Backdoor, Keylogger, Info stealer, Credential stealer, Loader Description (Accenture) Loki Bot is a resident loader, and password and cryptocurrency wallet stealer. Loki Bot captures passwords from browsers, as well as e-mail, FTP, SSH and poker clients. Information https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f37100e9-04b8-40ff-a39c-fe1d24a814cc Page 1 of 2 MITRE ATT&CK Malpedia AlienVault OTX Playbook Last change to this tool card: 14 March 2024 Download this tool card in JSON format All groups using tool LokiBot Changed Name Country Observed APT groups El Machete [Unknown] 2010-Mar 2022 Gorgon Group 2017-Jul 2020 Patchwork, Dropping Elephant 2013-Jun 2025 RATicate [Unknown] 2019 Sweed [Unknown] 2017-2019 5 groups listed (5 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f37100e9-04b8-40ff-a39c-fe1d24a814cc https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f37100e9-04b8-40ff-a39c-fe1d24a814cc Page 2 of 2