Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware LoFiSe

LoFiSe

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

LoFiSe is a Windows tool used by ToddyCat to locate and gather specific files from compromised systems. The malware performs low‑profile file discovery and staging for exfiltration, enabling the actor to collect targeted data without triggering many traditional detection methods. Security teams should monitor for unexplained activity within critical directories and block unauthorized outbound transfers involving user‑generated content.

Enhanced Description

LoFiSe is a Windows‑based malware component that has been observed in campaigns attributed to the threat actor ToddyCat since at least 2023. During intrusion, LoFiSe scans local file systems for documents and other artefacts deemed valuable by the attackers. Once identified, the files are copied or staged for exfiltration, allowing investigators to see which types of data the adversaries prioritize. The tool has been designed with a low‑profile footprint; it avoids creating obvious persistence mechanisms and instead relies on existing legitimate processes to carry out its activities. Because LoFiSe operates as an ancillary collection module rather than the primary malware payload, its behavior is relatively simple but effective. By focusing solely on discovery and collection, it can remain undetected by conventional anti‑virus engines while still providing a valuable data‑gleaning function for threat actors.

Key Capabilities

  • File system enumeration
  • Selective collection based on file type or location
  • Low‑profile execution leveraging legitimate processes
  • Data staging for exfiltration

ATT&CK Techniques

T1083
T1055
T1070
T1041

Recommended Actions

  • Deploy endpoint detection and response (EDR) to monitor for unusual file read/write patterns on protected directories.
  • Implement application whitelisting and restrict execution of unknown binaries in administrative paths.
  • Use network segmentation and monitor outbound traffic for abnormal data sizes or connections to suspicious hosts. "Detect and block known LoFiSe file hashes or strings via host intrusion prevention systems, and reference Kaspersky threat intelligence for updated signatures."

Suggested Tags

file-discovery
data-staging
ToddyCat
Windows-malware

Confidence Assessment

The available information is limited primarily to a single citation indicating LoFiSe’s role as a file discovery tool. While the core functionality—file enumeration and collection—is supported, details about execution vectors, persistence mechanisms, C2 infrastructure, and post‑exfiltration steps remain unknown. Consequently confidence in the full threat picture is low, with substantial gaps regarding how the malware is initially delivered, how it avoids detection, or what additional capabilities it may possess.

Description

LoFiSe has been used by ToddyCat since at least 2023 to identify and collect files of interest on targeted systems.(Citation: Kaspersky ToddyCat Check Logs October 2023)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.