Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware LODEINFO

LODEINFO

TLP:CLEAR
Family

AI Analysis

· 2 hours ago

Executive Summary

LODEINFO is a fileless Windows backdoor employed by MirrorFace against Japanese media and government targets. It operates from memory using PowerShell and WMI for persistence and remote execution, enabling stealthy data exfiltration. Security teams should monitor for anomalous in‑memory processes, unusual PowerShell scripts, and unauthorized scheduled tasks.

Enhanced Description

LODEINFO is a Windows‑only fileless backdoor first detected in 2020 and attributed to the actor MirrorFace. The malware operates entirely from memory, often leveraging legitimate Microsoft tools such as PowerShell and WMI for execution and persistence. While detailed technical information is scarce, LODEINFO has been observed establishing remote command‑and‑control channels and delivering additional payloads to compromise targeted systems. Operational reports indicate that LODEINFO has specifically targeted media, diplomatic, governmental, and public sector organizations in Japan, exploiting the perceived value of political and economic intelligence. The persistence mechanism typically involves modifying registry keys or leveraging scheduled tasks without leaving traditional file traces on disk. This approach hampers conventional endpoint detection methods and requires deeper behavioral monitoring within system memory and command‑line activity. In addition to remote execution capabilities, LODEINFO is known for exfiltrating collected data over encrypted channels, often disguising traffic as legitimate HTTPS or SMB sessions to avoid detection by basic network security controls.

Key Capabilities

  • Memory‑resident operation (fileless)
  • Persistence via registry modifications or scheduled tasks
  • Remote command execution using PowerShell/WMI
  • Data exfiltration over encrypted channels

ATT&CK Techniques

T1059
T1086
T1055
T1107

Recommended Actions

  • Enable memory integrity protection and monitor for unusual in‑memory binaries.
  • Deploy endpoint detection to flag unexplained PowerShell usage and WMI queries.
  • Implement network monitoring to detect anomalous HTTPS/SMB traffic from internal hosts.
  • Use script block logging and AppLocker to restrict execution of unknown scripts.
  • Keep OS, drivers, and security tools updated to mitigate exploitation of known vulnerabilities.

Suggested Tags

fileless
backdoor
targeted-attack
media-targets
diplomatic-targets
government-targets
Japan

Confidence Assessment

The data pool originates from a handful of public reports, leaving gaps in detailed technical behavior such as injection methods, persistence vectors beyond scheduled tasks, and specific command structures. Confidence is moderate regarding high‑level capabilities; finer granularity remains uncertain.

Description

LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: ITOCHU LODEINFO JAN 2024)(Citation: ESET MirrorFace DEC 2022)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.