GRIDINSOFT HELP CENTER

LokiBot: Credential Theft, Detection, and Removal

LokiBot (Loki Password Stealer)

What it is

LokiBot is a credential-stealing trojan that targets Windows and Android. It grabs passwords, cookies, and wallet data, can take screenshots, and sometimes opens a backdoor for more malware.

How it spreads – quick tour

  • Phishing emails with booby-trapped attachments

  • Fake updates, cracks, and repacked installers

  • Malicious links and sideloaded APKs on Android

What you may notice

  • Sudden re-logins or missing 2FA codes

  • Unknown browser extensions or redirects

  • New startup tasks or services you didn’t create

  • Data and battery spikes on Android, odd accessibility prompts

Remove it now

  1. Disconnect from the internet to stop data exfiltration.

  2. Run a full anti-malware scan, reboot, then scan again.

  3. From a clean device, change passwords and turn on MFA.

  4. Check startup items, tasks, services, and extensions; remove unknowns.

  5. On Android: uninstall suspicious apps, review Accessibility/Device admin settings, then rescan.

Prevent it

  • Install software only from official sources; avoid cracks and third-party app stores.

  • Keep Windows, Android, browsers, and Office updated; block macros by default.

  • Use reputable EDR/anti-malware and DNS/web filtering.

  • Enable MFA everywhere so stolen passwords are less useful.

After removing LokiBot

Local cleanup does not invalidate information that was already stolen. From a clean device, change passwords for accounts used or stored on the infected computer, revoke active sessions, and review email forwarding rules and recovery details. Prioritize email, password managers, financial services, remote access, and business accounts.

If a wallet seed phrase or private key was exposed, create a new wallet on a trusted device and move remaining assets; changing an application password does not replace the key. Review the credential-theft response steps, even when no unauthorized login is visible yet. For a business device, investigate other hosts and accounts because an infostealer can provide access for a later intrusion.

Helpful?

Glossary (0-9, A-Z)

Still can’t find an answer?

Send us a ticket and we will get back to you.

Submit a ticket