DOWNIISSA

S9021

Malware.View on attack.mitre.org

About this malware

DOWNIISSA is a shellcode downloader that has been used by MirrorFace since at least 2022 to deploy payloads, including the LODEINFO backdoor.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

DOWNIISSA code is base64 encoded and XOR encrypted.

T1055
Process Injection

DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe.

T1070.004
File Deletion

DOWNIISSA can delete files after download.

T1105
Ingress Tool Transfer

DOWNIISSA can download files to the compromised host.

T1106
Native API

DOWNIISSA can use the `URLDownloadToFileA()` API to download from remote resources.

T1140
Deobfuscate/Decode Files or Information

DOWNIISSA can decode strings prior to execution.

T1218.007
Msiexec

DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky LODEINFO OCT 2022 Open source
    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.