LO$R Logger v2: Turn Every Loss Into a Lesson

1253 Views 0 Replies sienna68
#
09-01-2025, 05:08 AM |
[Image: LOR-Logger-v2.png]What is LO$R Logger v2?LO$R Logger (short for Loki Password Stealer & Recorder) is a banking trojan and keylogger that first emerged in underground cybercrime forums. The v2 version represents a major upgrade, featuring:
 
  • Enhanced credential theft (banking logins, credit cards, crypto wallets)
  • Advanced evasion techniques (anti-VM, anti-sandbox, code obfuscation)
  • Modular plugin system (allowing attackers to add new features)
Key Features of LO$R Logger v21. Banking & Financial Data Theft
  • Web injects 
  • Form grabbing
  • Credit card harvesting 
  • Cryptocurrency theft
2. Keylogging & Screen Capture
  • Records keystrokes 
  • Takes screenshots 
  • Webcam hijacking
3. Anti-Detection & Evasion Techniques
  • Polymorphic code – Changes its signature to avoid AV detection.
  • Process injection – Runs inside legitimate processes (e.g., explorer.exe).
  • Virtual Machine (VM) evasion – Detects sandbox environments and shuts down.
  • Rootkit functionality – Hides files, registry keys, and network activity.
4. C2 (Command & Control) Communication
  • Tor-based C2 servers 
  • Encrypted exfiltration 
  • Telegram bot integration 
5. Persistence Mechanisms
  • Registry autorun keys 
  • DLL sideloading 
  • Task scheduler abuse 
Thread Info
Authorsienna68
Posted
Views1253
Replies0
Participants1

This board is for authorized security research only. Attacking systems without permission is illegal. The community follows responsible disclosure.