Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Loda

110
Global rank
108 infographic chevron month
Month rank
145 infographic chevron week
Week rank

Loda is a remote access trojan (RAT) that has been in active use among multiple threat actors since 2016. The malware’s functionality includes stealing passwords and other sensitive information, keylogging, capturing screenshots, and delivering other malicious payloads. Loda is typically distributed as part of phishing email campaigns.

RAT
Type
Morocco
Origin
Unknown
First seen
10 September, 2026
Last seen

How to analyze Loda with ANY.RUN

RAT
Type
Morocco
Origin
Unknown
First seen
10 September, 2026
Last seen

IOCs

IP addresses
138.252.131.215
40.8.195.179
170.152.242.52
54.233.180.158
74.220.199.6
210.171.58.203
137.87.99.163
210.153.191.83
25.243.55.92
213.133.94.133
215.241.245.86
210.168.137.88
107.36.31.109
113.143.138.111
66.62.183.77
92.183.233.66
210.229.165.153
84.129.161.208
190.139.187.252
213.168.208.28
Hashes
f7e4aae30ab2bda60bead5fd5a29a36685d768df007d3399d3047768babae200
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
751258bb040197c7c10683a74b38a1b1aef9c68ca9a58ce2168c8a62cb913371
4478f6fcfd2fc9be012668592bfbf6838a115d983f9d30171669b20cafe529b9
301bd9f16f94feedfae7a946a14bac38cb73c43efe6117bc5586835af03d7d6f
f957a4c261506484b53534a9be8931c02ec1a349b3f431a858f8215cecfec3f7
c04daeba7e7c4b711d33993ab4c51a2e087f98f4211aea0dcb3a216656ba0ab7
92eed84bd4d68a0945b42e1ca3a9a0a211d2f7268b8e4a633b3e6bcc6c9e3711
739b2dd012ea183895cc01116906f339c9aa1c0baabf6f22c8e59e25a0c12917
bf8cf01a18233cf567e7638e3115c7145ac0b09698a2ec85980e23826366d784
ea4580a816ad527e6cd5dc30ab5c69e2882f5790143b133d61d12b4a726fa27d
e7024049cbaf85410297320098a8f3fd20069f83b6114ef4289ffc33860b1472
1ee115c74ff59070e90b4cb4024c3fc1f065e3b7c02ea76bb82e78b79722d5c1
e5c2542e57a8888a3c63d62c7d48e203b1870e40d898f2c92caea8612af043b0
63a8e3782eba06f4a86691a101b64ed7a8d4e9415ca5eb3c0e669fe3db877928
82eaaa4105fa1df8fe516bec815a7634db6aabcd176726e63761ad315f2c43ef
94c3b96bdc73610cd926353c97b0918ec9515f7da64f57f15240d3966a5c2d38
35282a5b610de1d60d530ce2c9d315455740e0a88d83ede1c56f5a160010815b
61d081d7afc5f699460a4d34b0cd9ee1e81afaa0b03d9d47e0f38737724a29a2
Domains
slscr.update.microsoft.com
winnerscorner.gleeze.com
adclick.g.doubleclick.net
3xp3cts1aim.sbs
d.wanyouxi7.com
ftp.zhzy999.net
m.meta-dm.com
config.i.duba.net
abilityindisabilityindia.org
hnjgdl.geps.glodon.com
pvsa.gxfugy.cn
touvrlane.bet
cl.ssouy.com
download.pdf00.cn
infoc0.duba.net
toolshare.com.tr
www.blackhattoolz.com
static.ilclock.com
bravplo.click
update.cg100iii.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://62.60.226.140/files/unique2/file.exe
http://62.60.226.140/files/com/kliulij.exe
http://45.61.176.53/bin/screenconnect.clientsetup.exe
http://45.61.176.53/bin/support.client.exe
http://91.92.242.236/files-129312398/files/file_deaad5d12778941d.exe
http://91.92.242.236/files-129312398/files/file_3c7c16fb45b485e2.exe
http://91.92.242.236/files-129312398/files/file_ea7a051a82d4b3b5.exe
http://91.92.242.236/files-129312398/files/file_c02d1b6f3f7b2bea.exe
http://5.230.201.18/bin/support.client.exe
http://91.92.242.236/files-129312398/files/file_f560a93d91a75b5c.exe
http://5.230.201.18/bin/screenconnect.clientsetup.exe
http://193.178.158.107/1.exe
http://91.92.242.236/files-129312398/files/file_8eb65d0dcf9d4880.exe
Last Seen at
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 3785
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 4251
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 5556
comments 0

What is Loda RAT malware?

Loda is a remote access trojan that first appeared in 2016. It is written in AutoIT, a language designed for automating scripting on Windows systems, that is easy to learn and use. It is believed that the original creators behind Loda are the Kasablanka group, an advanced persistent threat (APT) from Morocco, which regularly published updated versions of the malware.

At the same time, the malware is also used by other threat actors, including YoroTrooper which has employed a variant of Loda malware to carry out assaults on various organizations around the world, with the most recent attacks occurring as early as 2023. TA558 is another APT that has implemented Loda in its malicious activities, primarily targeting hospitality businesses in Europe and North America.

Technical details of the Loda RAT malicious software

To make it difficult for security researchers to analyze its code, Loda RAT uses string obfuscation on most variables. At run time, Loda RAT deobfuscates the strings and initializes the variables accordingly. Another technique used by Loda RAT is function name randomization, involving randomly assigning names to functions in the code.

In order to evade detection, Loda replicates itself within the temporary files folder of the targeted computer and then executes the copy. Additionally, Loda RAT generates a scheduled task, which is configured to initiate itself automatically during system boot-up. After running, the malware reports key information about the system to its C&C server, including the IP address, OS version, and architecture.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

In terms of functionality, Loda possesses the standard set of RAT capabilities, which allow attackers to:

  • Access the infected computer via Remote Desktop Protocol (RDP).
  • Steal files and data.
  • Upload other malicious software onto the system and run it.
  • Record users’ keystrokes and mouse clicks.
  • Listen to the microphone.
  • Take webcam photos and screenshots
  • Communicate with the victim via a chat window.
  • Query WMI to obtain a list of all the antivirus solutions that are installed on the host system.

There is also an Android version of Loda RAT. It functions as a tracking application that can capture victims’ whereabouts and record any audio-based communication originating from the user. Additionally, it possesses the ability to monitor SMS messages and even make calls without users’ knowledge.

Execution process of Loda RAT

A sample of Loda RAT executed in the ANY.RUN interactive sandbox exposes the malware’s malicious activities and IOCs.

It follows a straightforward execution process. Loda first drops executables into the %appdata%, Startup, and Temp directories, then creates a service via schtasks to gain persistence, executes a Visual Basic script, and finally connects to the C&C server.

Loda RAT process tree

Loda RAT process tree

Distribution methods of the Loda RAT malware

Phishing email campaigns are the most common attack vector used by threat actors to infect victims’ systems with Loda. Typically, such emails contain attachments of different formats, including PDFs, executables, and Microsoft Office documents, embedded with malicious code. Some of the early instances of Loda RAT infections were carried out by exploiting the CVE-2017-11882 and CVE-2017-0199 vulnerabilities.

As mentioned above, Loda RAT is popular among various criminal groups. For instance, in 2019, TA558 utilized PowerPoint attachments injected with macros to distribute both Loda and Revenge RAT, while in 2022, the group switched to container formats (e.g., RAR) and expanded their payload selection to include AsyncRAT. Similarly, in 2022, the Kasablanka APT devised a multi-stage attack targeting government agencies, which employed .iso email attachments to spread Loda and WarZone RAT.

Conclusion

Loda remains a top cyber security threat, with no signs of slowing down. A large number of criminal actors take advantage of this malware’s configurable design and accessibility to conduct attacks against businesses and government organizations in different parts of the world. The best way to avoid compromising your system by accidentally downloading Loda is to steer clear of any unsolicited emails and take precautions before opening suspicious links and files. You can do it by analyzing them in an online sandbox like ANY.RUN. By uploading your sample to the platform, you quickly and safely gain the knowledge needed to prevent infection.

Try ANY.RUN for free – request a demo!

HAVE A LOOK AT

DarkGate screenshot
DarkGate
darkgate
DarkGate is a loader, which possesses extensive functionality, ranging from keylogging to crypto mining. Written in Delphi, this malware is known for the use of AutoIT scripts in its infection process. Thanks to this malicious software’s versatile architecture, it is widely used by established threat actors.
Read More
Gh0st RAT screenshot
Gh0st RAT
gh0st
Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.
Read More
Netwalker screenshot
Netwalker
netwalker ransomware
Netwalker is ransomware — it belongs to a malware family which encrypts files and demands users to pay a ransom to get their data back. Netwalker utilizes several sophisticated techniques, such as process hollowing and code obfuscation to target corporate victims.
Read More
Greatness screenshot
Greatness is a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals, even those with limited technical skills, to launch sophisticated phishing attacks primarily targeting Microsoft 365 (M365) credentials. It acts as a man-in-the-middle (MitM) proxy, facilitating credential theft and MFA bypass while providing affiliates with easy-to-use tools like attachment builders and Telegram notifications.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Roning Loader screenshot
Roning Loader
roning
RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.
Read More