Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupMirrorFace | MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.003 NTDS |
GroupMirrorFace | MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1005 Data from Local System |
GroupMirrorFace | MirrorFace gathered data and files of interest from victim's systems. |
| T1005 Data from Local System |
MalwareHiddenFace | HiddenFace can upload files from the victim machine to C2 nodes. |
| T1008 Fallback Channels |
MalwareHiddenFace | HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands. |
| T1021.001 Remote Desktop Protocol |
GroupMirrorFace | MirrorFace has used RDP to exfiltrate files of interest. |
| T1021.002 SMB/Windows Admin Shares |
GroupMirrorFace | MirrorFace has used SMB to copy malware between systems in compromised environments. |
| T1027 Obfuscated Files or Information |
MalwareNOOPLDR | NOOPLDR can use control flow flattening to help hide malicious code. |
| T1027.007 Dynamic API Resolution |
MalwareHiddenFace | HiddenFace can dynamically resolve Windows APIs. |
| T1027.013 Encrypted/Encoded File |
MalwareNOOPLDR | The NOOPLDR payload is encrypted with AES256-CBC. |
| T1027.016 Junk Code Insertion |
MalwareNOOPLDR | NOOPLDR can insert junk code to obfuscate malicious payloads. |
| T1033 System Owner/User Discovery |
GroupMirrorFace | MirrorFace has used Windows native tools to enumerate user information. |
| T1053.005 Scheduled Task |
MalwareHiddenFace | HiddenFace has used scheduled tasks for execution and persistence. |
| T1055 Process Injection |
MalwareNOOPLDR | NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe. |
| T1056.001 Keylogging |
MalwareLODEINFO | LODEINFO can capture keystrokes on targeted systems. |
| T1059.003 Windows Command Shell |
GroupMirrorFace | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation. |
| T1070.004 File Deletion |
MalwareNOOPLDR | NOOPLDR can delete a file containing configuration instructions after use. |
| T1070.004 File Deletion |
GroupMirrorFace | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment. |
| T1070.006 Timestomp |
MalwareHiddenFace | HiddenFace can alter timestamps for directory content on targeted machines. |
| T1074.002 Remote Data Staging |
GroupMirrorFace | MirrorFace has gathered data and files of interest on a single victim machine. |
| T1082 System Information Discovery |
MalwareNOOPLDR | NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys. |
| T1082 System Information Discovery |
MalwareHiddenFace | HiddenFace can enumerate the hostname and username of the compromised system. |
| T1082 System Information Discovery |
GroupMirrorFace | MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery. |
| T1083 File and Directory Discovery |
GroupMirrorFace | MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions. |
| T1087.002 Domain Account |
GroupMirrorFace | MirrorFace has used native Windows tools to obtain domain user information. |
| T1090.001 Internal Proxy |
MalwareHiddenFace | HiddenFace can act as an internal HTTP proxy within the targeted environment. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenFace | HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1105 Ingress Tool Transfer |
MalwareHiddenFace | HiddenFace can download files from the C2 to victim systems. |
| T1106 Native API |
MalwareNOOPLDR | NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection. |
| T1112 Modify Registry |
MalwareNOOPLDR | NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNOOPLDR | NOOPLDR can decrypt its payload prior to execution. |
| T1480 Execution Guardrails |
MalwareHiddenFace | HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found. |
| T1482 Domain Trust Discovery |
GroupMirrorFace | MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships. |
| T1518.001 Security Software Discovery |
MalwareHiddenFace | HiddenFace can identify processes identified with security applications and tooling. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLODEINFO | LODEINFO has used Registry run keys to set persistence. |
| T1552.006 Group Policy Preferences |
MalwareMirrorStealer | MirrorStealer can target Group Policy Preferences for credentials. |
| T1555 Credentials from Password Stores |
MalwareMirrorStealer | MirrorStealer has the ability to steal credentials from email clients. |
| T1555.003 Credentials from Web Browsers |
MalwareMirrorStealer | MirrorStealer can steal credentials stored in browsers. |
| T1560.001 Archive via Utility |
GroupMirrorFace | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1571 Non-Standard Port |
MalwareHiddenFace | HiddenFace's passive mode listens on TCP 47000. |
| T1573.002 Asymmetric Cryptography |
MalwareHiddenFace | HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2. |
| T1574.001 DLL |
GroupMirrorFace | MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading. |
| T1574.001 DLL |
MalwareNOOPLDR | NOOPLDR can be executed via sideloading. |
| T1588.002 Tool |
GroupMirrorFace | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike. |
| T1686.003 Windows Host Firewall |
MalwareHiddenFace | HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.