Skip to content

Malware

L0rdix

aka lordix

L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018.

L0rdix, also known as lordix, is a Windows malware family.

Background

L0rdix is a versatile .NET remote access tool (RAT) that was first seen advertised on underground forums in November 2018. By default it ships with eight commands, though operators can define and add their own. The built-in set includes:

Download and execute Update Open page (visible) Open page (invisible) Cmd Kill process Upload file HTTP Flood

L0rdix can extract credentials from common web browsers and steal data from crypto wallets and a target's clipboard. Optionally, L0rdix can deploy a cryptominer (XMRig) to its bots.


Source: Malpedia (Fraunhofer FKIE).