> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: LokiBot/ViriBack Command-and-Control Infrastructure
- URL: https://darkwebinformer.com/ioc-alert-lokibot-viriback-command-and-control-infrastructure/
- Published: 2025-09-04T19:06:21.000Z
- Updated: 2025-09-04T22:19:35.000Z
- Author: Dark Web Informer
- Tags: IOC

📖 **Overview**  
A domain-based indicator has been identified linked to **LokiBot** credential-stealing malware and **ViriBack** C2 operations. The site presents a simple login portal with CAPTCHA validation, suggesting its use as a botnet control panel. Confidence is assessed at 50%, indicating a possible but not yet fully confirmed association.

---

📌 **Key Details**

| Field           | Information                |
| --------------- | -------------------------- |
| **Type**        | Domain                     |
| **Indicator**   | electrico\[.\]co\[.\]zw    |
| **Threat Type** | Botnet C2                  |
| **Malware**     | win.lokipws                |
| **Confidence**  | 50%                        |
| **Date**        | 04 Sep 2025 – 18:36:02 UTC |
| **Tags**        | LokiBot, ViriBack          |
| **Reporter**    | abuse\_ch                  |

---

🔎 **URLScan Result**  
Page Title: Auth  
Screenshot: <https://urlscan.io/screenshots/01991601-311c-70d8-8967-9174e52d9e98.png>  
Result: [https://urlscan.io/result/01991601-311c-70d8-8967-9174e52d9e98/](https://urlscan.io/result/01991601-311c-70d8-8967-9174e52d9e98)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/09/873487623548675832764567521.jpg)

---

📡 **Related Intelligence**  
WHOIS Record: <https://who.is/whois/electrico.co.zw>  
VirusTotal Report: <https://www.virustotal.com/gui/domain/electrico.co.zw>  
Reference: <https://tracker.viriback.com/index.php?q=electrico.co.zw>

---

🛡️ **Defensive Guidance**

- Block `electrico[.]co[.]zw` at DNS, proxy, and endpoint layers.
- Monitor for LokiBot credential harvesting activity.
- Hunt for ViriBack artifacts across infected endpoints.
- Review proxy/firewall logs for traffic to the suspected C2 panel.

---

⚠️ Confidence is **moderate (50%)**, meaning this IOC should be treated with caution until corroborated by additional telemetry.