ATT&CKReferencesKaspersky LODEINFO OCT 2022

Kaspersky LODEINFO OCT 2022

Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareLODEINFO

LODEINFO can enumerate the MAC address of the compromised host.

T1027.013
Encrypted/Encoded File
MalwareDOWNIISSA

DOWNIISSA code is base64 encoded and XOR encrypted.

T1027.013
Encrypted/Encoded File
MalwareLODEINFO

The LODEINFO loader module contains XOR-encrypted shellcode.

T1027.015
Compression
MalwareLODEINFO

LODEINFO components have been compressed with zip for delivery.

T1055
Process Injection
MalwareDOWNIISSA

DOWNIISSA can inject shellcode directly into process memory including WINWORD.exe and msiexec.exe.

T1070.004
File Deletion
MalwareDOWNIISSA

DOWNIISSA can delete files after download.

T1105
Ingress Tool Transfer
MalwareDOWNIISSA

DOWNIISSA can download files to the compromised host.

T1106
Native API
MalwareDOWNIISSA

DOWNIISSA can use the `URLDownloadToFileA()` API to download from remote resources.

T1140
Deobfuscate/Decode Files or Information
MalwareDOWNIISSA

DOWNIISSA can decode strings prior to execution.

T1204.002
Malicious File
GroupMirrorFace

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.

T1204.002
Malicious File
MalwareLODEINFO

LODEINFO has been executed via victims opening malicious email attachments.

T1218.007
Msiexec
MalwareDOWNIISSA

DOWNIISSA can create an instance of msiexec.exe and inject LODEINFO shellcode into the memory of the process.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1566.001
Spearphishing Attachment
GroupMirrorFace

MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.

T1574.001
DLL
MalwareLODEINFO

LODEINFO can use legitimate EXE files to sideload malicious DLLs.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.