LevelBlue A.I CyberSecurity Scoring
LevelBlue
Company Information
Website:http://www.levelblue.com/
Employees number:814
Number of followers:115,083
NAICS:541514
Industry Type:Computer and Network Security
Homepage:levelblue.com
LevelBlue Risk Score (AI oriented)
Between 700 and 749
LevelBlueComputer and Network Security
Updated:
25/06/2026
25/06/2026
739/1000
Moderate
Ba
LevelBlue Global Score (TPRM)
xxxx
LevelBlueComputer and Network Security
Score locked

LevelBlueModerate
Current Score
739Ba (MODERATE)
01000
2 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
740
JULY 2026
740
JUNE 2026
739
MAY 2026
757
Cyber Attack
01 May 2026 • LevelBlue
LevelBlue: LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials
LokiBot Resurfaces in Sophisticated Multi-Stage Credential Theft Campaign
738
CRITICAL-19
LEV1782397631
LokiBot Resurfaces in Sophisticated Multi-Stage Credential Theft Campaign
LokiBot, one of the longest-active credential-stealing malware families, has reemerged in a new campaign combining legacy techniques with modern evasion tactics. First advertised in 2015 by threat actors "lokistov" and "carter," the malware gained traction after its source code leaked in 2018, leading to forks with expanded capabilities, including Android support, keylogging, and remote access. Today, LokiBot targets credentials from over 100 applications, including browsers, cryptocurrency wallets, email clients, and FTP tools.
Security researchers at LevelBlue uncovered the latest campaign, which begins with a phishing email containing a malicious JScript attachment. When executed, the obfuscated script triggers a multi-stage infection chain designed to evade detection and erase traces if interrupted. The attack proceeds as follows:
1. Initial Execution: The JScript file runs via Windows Script Host, decoding a Base64-encoded PowerShell script stored in C:\Temp under a random filename.
2. Payload Delivery: The PowerShell script decrypts a .NET assembly using XOR encryption, loading it directly into memory to avoid disk-based detection. The assembly, obfuscated with ConfuserEx, acts as an injector.
3. Process Injection: The malware spawns a legitimate aspnet_compiler.exe process, injecting the final LokiBot payload into its memory space a technique that blends malicious activity with trusted system processes.
4. Credential Theft: Once active, LokiBot creates a mutex (using the MD5 hash of the machine’s registry ID) to prevent duplicate infections. It then harvests credentials from targeted applications, compresses the stolen data with aPLib, and exfiltrates it to a command-and-control (C2) server via 3DES-encrypted communication.
5. Persistence Attempts: While newer samples include a broken persistence mechanism due to a flawed decryption routine, the malware still attempts to establish a foothold via registry run keys.
The campaign’s C2 infrastructure includes domains such as kbfvzoboss.bid, alphastand.trade, and the IP address 158.94.211.95, with exfiltration endpoints like http://158.94.211.95/kelly/five/fre.php. LokiBot’s stealth is further enhanced by runtime API resolution (avoiding direct imports) and reflective loading to bypass traditional detection methods.
Despite its age, LokiBot remains a persistent threat due to its low cost, ease of use, and continuous evolution. Successful infections grant attackers access to sensitive credentials, enabling account takeovers, data theft, and further compromise of individuals and organizations. LevelBlue’s analysis highlights the malware’s adaptability, blending obfuscation, process injection, and memory-resident execution to evade modern defenses.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
757
MARCH 2026
756
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
757
Vulnerability
23 Dec 2025 • LevelBlue
Tenable and LevelBlue: LevelBlue Integrates Unlimited Tenable Vulnerability Scanning Into Its USM Platform
756
LOW-1
TENLEV1766519861
LevelBlue Expands Tenable Partnership to Offer Unlimited Vulnerability Scanning at No Extra Cost
LevelBlue has deepened its collaboration with Tenable, now providing unlimited enterprise-grade vulnerability scanning for all customers using its Unified Security Management (USM) platform—without additional fees. The move aims to address a persistent challenge in vulnerability management: not the lack of scanning, but the ability to act on findings effectively.
While unlimited scanning increases visibility, the real shift lies in prioritization, remediation, and operational execution. The USM platform enhances raw scan data with advanced filtering, categorization, and risk-based prioritization, helping teams focus on critical vulnerabilities. Automated executive reporting also tracks risk posture over time, aiding compliance and leadership oversight.
For organizations requiring broader coverage—such as attack surface monitoring (ASM), OT, web applications, or dark web exposure—LevelBlue offers a seamless upgrade to its fully managed vulnerability program. Since the scanner is pre-configured, migration involves only a license change, reducing operational friction.
Customers retain flexibility: they can keep existing Tenable licenses (via bi-directional integration with Tenable One or Security Center) or consolidate under the embedded USM scanner, simplifying vendor management and potentially lowering costs. Managed delivery options further streamline operations, allowing LevelBlue to handle Tenable instances while maintaining client visibility.
The integration also reshapes how MSSPs and partners package vulnerability services. By embedding enterprise-grade scanning at no extra cost, LevelBlue shifts scanning from a premium add-on to a baseline capability. This approach contrasts with competitors who treat vulnerability scanning as an incremental expense, instead positioning it as part of a unified security stack.
Beyond scanning, the update emphasizes exposure management—correlating Tenable findings with live detections, contextual prioritization, and end-to-end remediation tracking. The result is a continuous, actionable view of risk, moving beyond static reports to real-time reduction of exposure.
For security teams and service providers, the change signals a broader industry trend: reducing tool sprawl while improving outcomes through tighter integration between vulnerability data and security operations.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
NOVEMBER 2025
757
OCTOBER 2025
757
SEPTEMBER 2025
757
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for LevelBlue ??
What was LevelBlue's A.I Rankiteo Cyber Score in July 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in June 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in May 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in April 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in March 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in February 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in January 2026 ??
What was LevelBlue's A.I Rankiteo Cyber Score in December 2025 ??
What was LevelBlue's A.I Rankiteo Cyber Score in November 2025 ??
What was LevelBlue's A.I Rankiteo Cyber Score in October 2025 ??
What was LevelBlue's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on LevelBlue's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with LevelBlue ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view LevelBlue's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?