LODEINFO

S9020

Malware.View on attack.mitre.org

About this malware

LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.

Techniques used32

Procedure examples32

TechniqueProcedure example
T1001.001
Junk Data

LODEINFO can append C2 communication with randomly generated junk data.

T1005
Data from Local System

LODEINFO can upload files from infected hosts to the C2.

T1016
System Network Configuration Discovery

LODEINFO can enumerate the MAC address of the compromised host.

T1018
Remote System Discovery

LODEINFO can run `net view` and `net view /domain` for network discovery.

T1027
Obfuscated Files or Information

LODEINFO has used control flow flattening to obfuscate code.

T1027.007
Dynamic API Resolution

LODEINFO can use a hashing algorithm to dynamically resolve API function addresses.

T1027.013
Encrypted/Encoded File

The LODEINFO loader module contains XOR-encrypted shellcode.

T1027.015
Compression

LODEINFO components have been compressed with zip for delivery.

T1027.016
Junk Code Insertion

LODEINFO has inserted junk code to obstruct code analysis.

T1033
System Owner/User Discovery

LODEINFO can identify the associated username on targeted machines.

T1041
Exfiltration Over C2 Channel

LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server.

T1047
Windows Management Instrumentation

LODEINFO can execute commands with WMI.

T1055
Process Injection

LODEINFO can inject shellcode into the memory of compromised hosts.

T1056.001
Keylogging

LODEINFO can capture keystrokes on targeted systems.

T1057
Process Discovery

LODEINFO can kill a process using specific process ID.

View all 32 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. ESET MirrorFace DEC 2022 Open source
    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.
  2. ITOCHU LODEINFO JAN 2024 Open source
    ITOCHU. (2024, January 24). The Endless Struggle Against APT10: Insights from LODEINFO v0.6.6 - v0.7.3 Analysis. Retrieved April 17, 2026.
  3. Kaspersky LODEINFO OCT 2022 Open source
    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.