Executive Summary
LoFiSe is a Windows tool used by ToddyCat to locate and gather specific files from compromised systems. The malware performs low‑profile file discovery and staging for exfiltration, enabling the actor to collect targeted data without triggering many traditional detection methods. Security teams should monitor for unexplained activity within critical directories and block unauthorized outbound transfers involving user‑generated content.
Enhanced Description
LoFiSe is a Windows‑based malware component that has been observed in campaigns attributed to the threat actor ToddyCat since at least 2023. During intrusion, LoFiSe scans local file systems for documents and other artefacts deemed valuable by the attackers. Once identified, the files are copied or staged for exfiltration, allowing investigators to see which types of data the adversaries prioritize. The tool has been designed with a low‑profile footprint; it avoids creating obvious persistence mechanisms and instead relies on existing legitimate processes to carry out its activities. Because LoFiSe operates as an ancillary collection module rather than the primary malware payload, its behavior is relatively simple but effective. By focusing solely on discovery and collection, it can remain undetected by conventional anti‑virus engines while still providing a valuable data‑gleaning function for threat actors.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information is limited primarily to a single citation indicating LoFiSe’s role as a file discovery tool. While the core functionality—file enumeration and collection—is supported, details about execution vectors, persistence mechanisms, C2 infrastructure, and post‑exfiltration steps remain unknown. Consequently confidence in the full threat picture is low, with substantial gaps regarding how the malware is initially delivered, how it avoids detection, or what additional capabilities it may possess.
LoFiSe has been used by ToddyCat since at least 2023 to identify and collect files of interest on targeted systems.(Citation: Kaspersky ToddyCat Check Logs October 2023)