Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareLODEINFO | LODEINFO can append C2 communication with randomly generated junk data. |
| T1005 Data from Local System |
MalwareLODEINFO | LODEINFO can upload files from infected hosts to the C2. |
| T1027.007 Dynamic API Resolution |
MalwareLODEINFO | LODEINFO can use a hashing algorithm to dynamically resolve API function addresses. |
| T1027.013 Encrypted/Encoded File |
MalwareLODEINFO | The LODEINFO loader module contains XOR-encrypted shellcode. |
| T1047 Windows Management Instrumentation |
MalwareLODEINFO | LODEINFO can execute commands with WMI. |
| T1055 Process Injection |
MalwareLODEINFO | LODEINFO can inject shellcode into the memory of compromised hosts. |
| T1057 Process Discovery |
MalwareLODEINFO | LODEINFO can kill a process using specific process ID. |
| T1082 System Information Discovery |
MalwareLODEINFO | LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname. |
| T1105 Ingress Tool Transfer |
MalwareLODEINFO | LODEINFO has the ability to download additional files from the C2. |
| T1106 Native API |
MalwareLODEINFO | LODEINFO can use Windows APIs such as `VirtualAllocEx()`, `WriteProcessMemory()`, `CreateRemoteThread()`, `NtAllocateVirtualMemory()`, `NtWriteVirtualMemory()`, and `RtlCreateUserThread()` to enable memory injection of shellcode. |
| T1113 Screen Capture |
MalwareLODEINFO | LODEINFO has the ability to take screenshots. |
| T1124 System Time Discovery |
MalwareLODEINFO | LODEINFO can capture system time to send to the C2. |
| T1480 Execution Guardrails |
MalwareLODEINFO | LODEINFO can halt execution if the “en_US” locale is identified on a victim's machine. |
| T1486 Data Encrypted for Impact |
MalwareLODEINFO | LODEINFO can incorporate a ransom command to encrypt specified files and folders. |
| T1573.001 Symmetric Cryptography |
MalwareLODEINFO | LODEINFO can encrypt C2 communication with a hardcoded (NV4HDOeOVyL) Vigenere cipher key. |
| T1614.001 System Language Discovery |
MalwareLODEINFO | LODEINFO can looks for the “en_US” locale on the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.