Home/Threat Actor/Lokorrito
Threat Actor

Lokorrito

lokorrito · brazil · active since 2018-01

Lokorrito is a smaller Brazilian-origin banking trojan family operationally tracked by ESET researchers as part of the broader Brazilian-origin banking trojan family ecosystem.

operates with Brazilian Portuguese language spam email distribution, banking website overlay attacks against Brazilian banking institutions, keystroke logging, screen capture, and clipboard hijacking for transaction redirection, operational tradecraft consistent with ecosystem baseline.

does not display significantly distinctive operational tradecraft beyond Brazilian-origin banking malware ecosystem baseline.

primary targeting of Brazilian banking customers with selective Latin American expansion.

thin public technical documentation relative to larger families in the ecosystem.

curated for LATAM banking malware ecosystem completeness alongside Banbra, Bizarro, Casbaneiro, Grandoreiro, Guildma/Astaroth, Javali, Melcoz, Mekotio, Amavaldo, and Krachulka.

brazil confidence: medium 5 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Lokorrito is a smaller Brazilian-origin banking trojan family operationally tracked by ESET researchers as part of the broader ESET-led research initiative cataloguing Brazilian-origin banking trojan families. The cluster operates within the broader Brazilian-origin banking malware ecosystem with operational characteristics consistent with the ecosystem baseline, Brazilian Portuguese language spam email distribution, banking website overlay attacks against Brazilian banking institutions, keystroke logging of banking authentication credentials, screen capture of banking session content, and clipboard hijacking for banking transaction redirection. Lokorrito does not display significantly distinctive operational tradecraft beyond the Brazilian-origin banking malware ecosystem baseline, operationally distinct from Bizarro (which demonstrated European banking targeting expansion, MSI installer distribution tradecraft, and cloud storage C2 abuse, bizarro.yaml) and operationally distinct from the larger families with more operationally-significant public-record documentation (Banbra, Casbaneiro, Grandoreiro, Guildma / Astaroth, Mekotio).

The cluster is curated for LATAM banking malware ecosystem completeness as part of the broader Brazilian-origin banking trojan family panorama in this corpus. The entry is structurally significant for ecosystem completeness rather than for deep technical tradecraft analysis. Analysts requiring technical depth on the Brazilian banking malware ecosystem should prioritize the Banbra, Bizarro, Casbaneiro, Grandoreiro, Guildma / Astaroth, and Mekotio entries.

Aliases

5
lokorritolokorrito operatorslokorrito banking trojanlokorrito clusterlokorrito_brazilian_banking_cluster

Notable Campaigns

2
2019-2024ESET Lokorrito Banking Trojan Tracking and Documentation
2018-2025Lokorrito Operational Position Within Brazilian-Origin Banking Malware Ecosystem

Attribution & Reporting

Attributed by
ESETKasperskyBrazilian Federal Police (Policia Federal)Trend Micro
Key reporting
reportESET WeLiveSecurity: Lokorrito Latin American Banking Trojan Analysis
reportESET WeLiveSecurity: Brazilian Banking Trojan Family Evolution Series
reportKaspersky Securelist: Brazilian Banking Trojan Ecosystem Coverage
reportTrend Micro: Brazilian Banking Malware Ecosystem Research
reportMalpedia Malware Profile: Lokorrito

Operational

State sponsor

Cybercriminal cluster of Brazilian-origin operators responsible for developing, distributing, and operating the Lokorrito banking trojan family, a Brazilian-origin banking malware family operating within the broader Brazilian-origin banking trojan ecosystem. The cluster was tracked by ESET researchers and adjacent industry analysis as part of the broader ESET-led research initiative cataloguing Brazilian-origin banking trojan families across multiple years of operational tracking. Lokorrito represents one of the smaller and operationally-thinner-documented families in the broader Brazilian-origin banking malware ecosystem, operationally distinct from but operating in parallel with the more operationally-significant families curated separately in this corpus including Banbra (banbra.yaml, foundational Brazilian banking trojan), Bizarro (bizarro.yaml, European targeting expansion), Casbaneiro (casbaneiro.yaml), Grandoreiro (grandoreiro.yaml), Guildma / Astaroth (guildma_astaroth.yaml), Javali (javali.yaml), Melcoz (melcoz.yaml), Mekotio (mekotio.yaml), Amavaldo (amavaldo.yaml), and Krachulka (krachulka.yaml).

The cluster operators have not been individually indicted or publicly named. Industry analysis (ESET, Kaspersky, Brazilian Federal Police investigative reporting) has assessed the cluster as Brazilian-origin based on operational tradecraft characteristics, Brazilian Portuguese language strings in malware samples, and operational targeting profile (overwhelming focus on Brazilian banking institutions and Brazilian banking customers). The cluster operates as a financially-motivated cybercriminal operation with no known state sponsorship.

Motivations
financial_gain, banking_credential_theft, banking_fraud_operations, brazilian_retail_banking_targeting
Sectors
Regions

Detection Blind Spots

51 techniques
Across this actor’s 51 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)47/51 · 92%
Analytics (MITRE CAR)17/51 · 33%
Runtime / container (Falco)7/51 · 13%
File / malware (YARA)1/51 · 1%
Network (Suricata/Snort)14/51 · 27%
Vuln scan (Nuclei)0/51 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SPAM EMAIL DISTRIBUTION KITS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin