ATT&CKReferencesKaspersky LODEINFO Part II OCT 2022

Kaspersky LODEINFO Part II OCT 2022

Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

T1005
Data from Local System
MalwareLODEINFO

LODEINFO can upload files from infected hosts to the C2.

T1027.007
Dynamic API Resolution
MalwareLODEINFO

LODEINFO can use a hashing algorithm to dynamically resolve API function addresses.

T1027.013
Encrypted/Encoded File
MalwareLODEINFO

The LODEINFO loader module contains XOR-encrypted shellcode.

T1047
Windows Management Instrumentation
MalwareLODEINFO

LODEINFO can execute commands with WMI.

T1055
Process Injection
MalwareLODEINFO

LODEINFO can inject shellcode into the memory of compromised hosts.

T1057
Process Discovery
MalwareLODEINFO

LODEINFO can kill a process using specific process ID.

T1082
System Information Discovery
MalwareLODEINFO

LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname.

T1105
Ingress Tool Transfer
MalwareLODEINFO

LODEINFO has the ability to download additional files from the C2.

T1106
Native API
MalwareLODEINFO

LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode.

T1113
Screen Capture
MalwareLODEINFO

LODEINFO has the ability to take screenshots.

T1124
System Time Discovery
MalwareLODEINFO

LODEINFO can capture system time to send to the C2.

T1480
Execution Guardrails
MalwareLODEINFO

LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine.

T1486
Data Encrypted for Impact
MalwareLODEINFO

LODEINFO can incorporate a ransom command to encrypt specified files and folders.

T1573.001
Symmetric Cryptography
MalwareLODEINFO

LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key.

T1614.001
System Language Discovery
MalwareLODEINFO

LODEINFO can looks for the “en_US” locale on the victim’s machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.