Malware.View on attack.mitre.org
LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
LODEINFO can append C2 communication with randomly generated junk data. |
| T1005 Data from Local System |
LODEINFO can upload files from infected hosts to the C2. |
| T1016 System Network Configuration Discovery |
LODEINFO can enumerate the MAC address of the compromised host. |
| T1018 Remote System Discovery |
LODEINFO can run `net view` and `net view /domain` for network discovery. |
| T1027 Obfuscated Files or Information |
LODEINFO has used control flow flattening to obfuscate code. |
| T1027.007 Dynamic API Resolution |
LODEINFO can use a hashing algorithm to dynamically resolve API function addresses. |
| T1027.013 Encrypted/Encoded File |
The LODEINFO loader module contains XOR-encrypted shellcode. |
| T1027.015 Compression |
LODEINFO components have been compressed with zip for delivery. |
| T1027.016 Junk Code Insertion |
LODEINFO has inserted junk code to obstruct code analysis. |
| T1033 System Owner/User Discovery |
LODEINFO can identify the associated username on targeted machines. |
| T1041 Exfiltration Over C2 Channel |
LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server. |
| T1047 Windows Management Instrumentation |
LODEINFO can execute commands with WMI. |
| T1055 Process Injection |
LODEINFO can inject shellcode into the memory of compromised hosts. |
| T1056.001 Keylogging |
LODEINFO can capture keystrokes on targeted systems. |
| T1057 Process Discovery |
LODEINFO can kill a process using specific process ID. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.