Executive Summary
LODEINFO is a fileless Windows backdoor employed by MirrorFace against Japanese media and government targets. It operates from memory using PowerShell and WMI for persistence and remote execution, enabling stealthy data exfiltration. Security teams should monitor for anomalous in‑memory processes, unusual PowerShell scripts, and unauthorized scheduled tasks.
Enhanced Description
LODEINFO is a Windows‑only fileless backdoor first detected in 2020 and attributed to the actor MirrorFace. The malware operates entirely from memory, often leveraging legitimate Microsoft tools such as PowerShell and WMI for execution and persistence. While detailed technical information is scarce, LODEINFO has been observed establishing remote command‑and‑control channels and delivering additional payloads to compromise targeted systems. Operational reports indicate that LODEINFO has specifically targeted media, diplomatic, governmental, and public sector organizations in Japan, exploiting the perceived value of political and economic intelligence. The persistence mechanism typically involves modifying registry keys or leveraging scheduled tasks without leaving traditional file traces on disk. This approach hampers conventional endpoint detection methods and requires deeper behavioral monitoring within system memory and command‑line activity. In addition to remote execution capabilities, LODEINFO is known for exfiltrating collected data over encrypted channels, often disguising traffic as legitimate HTTPS or SMB sessions to avoid detection by basic network security controls.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The data pool originates from a handful of public reports, leaving gaps in detailed technical behavior such as injection methods, persistence vectors beyond scheduled tasks, and specific command structures. Confidence is moderate regarding high‑level capabilities; finer granularity remains uncertain.
LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: ITOCHU LODEINFO JAN 2024)(Citation: ESET MirrorFace DEC 2022)