PULSE NAME
December 23rd, 2025 - CryptoGen Cyber Threat Intelligence Advisory #8802 - Arcane Werewolf Adopts Loki 2.1 Malware in Targeted Espionage Attacks
WHITE Arcane Werewolf cryptocti 2025-12-22 Modified: 2025-12-22
27
IOCs
MEDIUM VOLUME
The cyber espionage group Arcane Werewolf is deploying the upgraded Loki 2.1 malware in targeted attacks against organizations using phishing based delivery methods. The new version improves stealth by executing malicious code in memory, making detection more challenging. It is designed to maximize damage while avoiding detection systems.
Indicators of Compromise (5 / 27 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0fb8c76db4554c7454b8fbc02067e757 MD5 of 6ccd834fdbba07cf071e3c6de703fbc7f9de10584df127ced27537db2e1a5a03 2025-12-22
FileHash-MD5 0fc962b63b625b7dc3d89c1784ccd2ae MD5 of e90f7f8594333e0a955a1daccbf5e9030ea86fa3c5c39f58b69d313304020fdd 2025-12-22
FileHash-MD5 3f98636c3c5748befc153d2dc53b8a41 MD5 of 7fbb29f8724fddfb32b29543e046cf4aceab8f10e5120150f58d7a119162c631 2025-12-22
FileHash-MD5 4bba14d3ae096c8d399537fc4f1c1b31 MD5 of 5f1d3992e426f47b572af12160f3cc7ac6c90634b17fd6a087eb1644a60a71f8 2025-12-22
FileHash-MD5 6ad480ec54b7c36d69a498f1404270a1 MD5 of e45a1fca84ea0de58f88fe8930b0309f9d736b7384a12f01b7843a9f6469d64b 2025-12-22