LODEINFO

MITRE ATT&CK: S9020 View on attack.mitre.org

Aliases: LODEINFO

First seen
2020-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:09:04

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:jp

Context

LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.

Detection coverage

  • 1 YARA rules
  • 570 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Junk Data (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • DLL (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Compression (attack-pattern)
  • Keylogging (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Screen Capture (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Dynamic API Resolution (attack-pattern)
  • System Time Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Process Injection (attack-pattern)
  • Malicious File (attack-pattern)
  • Native API (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Lodeinfo_Auto (yara-rule)

Reports & references

  • ESET — Unmasking Mirrorface Operation Liberalface Targeting Japanese Political Entities (report)
  • Trend Micro — Lodeinfo Campaign Of Earth Kasha (report)
  • blogs.jpcert.or.jp — Mirrorface Attack Against Japanese Organisations (report)
  • Kaspersky — 107742 (report)
  • Kaspersky — 107745 (report)
  • macnica.net — Mpressioncss Ta Report 2019 4 En (report)
  • macnica.net — Mpressioncss Ta Report 2019 4 (report)
  • Kaspersky — 99204 (report)
  • web-assets.esetstatic.com — Eset Apt Activity Report Q2 2023 Q3 2023 (report)
  • jsac.jpcert.or.jp — Jsac2024 2 7 Hara Shoji Higashi Vickie Su Nick Dai En (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lodeinfo (report)
  • blogs.jpcert.or.jp — Lodeinfo 2 (report)
  • blogs.jpcert.or.jp — Malware Lodeinfo Targeting Japan (report)
  • blogs.jpcert.or.jp — Lodeinfo (report)
  • twitter.com — 1351355443730255872 (report)
  • youtube.com — Watch (report)
  • cyberandramen.net — Analysis Of Lodeinfo Maldoc (report)
  • jsac.jpcert.or.jp — Jsac2023 1 6 Minakawa Saika Kubokawa En (report)
  • blogs.jpcert.or.jp — Lodeinfo 3 (report)
  • macnica.co.jp — Cyberespionage Report 2023 (report)
  • blog-en.itochuci.co.jp — 134100 (report)
  • MITRE ATT&CK — S9020 (report)

External references