LODEINFO
MITRE ATT&CK: S9020 View on attack.mitre.org
Aliases: LODEINFO
- First seen
- 2020-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:09:04
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:jp
Context
LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.
Detection coverage
- 1 YARA rules
- 570 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Junk Data (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- DLL (attack-pattern)
- Local Data Staging (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Remote System Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Execution Guardrails (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- System Language Discovery (attack-pattern)
- Compression (attack-pattern)
- Keylogging (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Screen Capture (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- System Time Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Process Injection (attack-pattern)
- Malicious File (attack-pattern)
- Native API (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Used by threat actors
- MirrorFace (threat-actor)
Detection rules
- MALPEDIA_Win_Lodeinfo_Auto (yara-rule)
Reports & references
- ESET — Unmasking Mirrorface Operation Liberalface Targeting Japanese Political Entities (report)
- Trend Micro — Lodeinfo Campaign Of Earth Kasha (report)
- blogs.jpcert.or.jp — Mirrorface Attack Against Japanese Organisations (report)
- Kaspersky — 107742 (report)
- Kaspersky — 107745 (report)
- macnica.net — Mpressioncss Ta Report 2019 4 En (report)
- macnica.net — Mpressioncss Ta Report 2019 4 (report)
- Kaspersky — 99204 (report)
- web-assets.esetstatic.com — Eset Apt Activity Report Q2 2023 Q3 2023 (report)
- jsac.jpcert.or.jp — Jsac2024 2 7 Hara Shoji Higashi Vickie Su Nick Dai En (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lodeinfo (report)
- blogs.jpcert.or.jp — Lodeinfo 2 (report)
- blogs.jpcert.or.jp — Malware Lodeinfo Targeting Japan (report)
- blogs.jpcert.or.jp — Lodeinfo (report)
- twitter.com — 1351355443730255872 (report)
- youtube.com — Watch (report)
- cyberandramen.net — Analysis Of Lodeinfo Maldoc (report)
- jsac.jpcert.or.jp — Jsac2023 1 6 Minakawa Saika Kubokawa En (report)
- blogs.jpcert.or.jp — Lodeinfo 3 (report)
- macnica.co.jp — Cyberespionage Report 2023 (report)
- blog-en.itochuci.co.jp — 134100 (report)
- MITRE ATT&CK — S9020 (report)