ATT&CKReferencesTrend Micro Earth Kasha NOV 2024

Trend Micro Earth Kasha NOV 2024

Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples46

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupMirrorFace

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.003
NTDS
GroupMirrorFace

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1005
Data from Local System
GroupMirrorFace

MirrorFace gathered data and files of interest from victim's systems.

T1005
Data from Local System
MalwareHiddenFace

HiddenFace can upload files from the victim machine to C2 nodes.

T1008
Fallback Channels
MalwareHiddenFace

HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands.

T1021.001
Remote Desktop Protocol
GroupMirrorFace

MirrorFace has used RDP to exfiltrate files of interest.

T1021.002
SMB/Windows Admin Shares
GroupMirrorFace

MirrorFace has used SMB to copy malware between systems in compromised environments.

T1027
Obfuscated Files or Information
MalwareNOOPLDR

NOOPLDR can use control flow flattening to help hide malicious code.

T1027.007
Dynamic API Resolution
MalwareHiddenFace

HiddenFace can dynamically resolve Windows APIs.

T1027.013
Encrypted/Encoded File
MalwareNOOPLDR

The NOOPLDR payload is encrypted with AES256-CBC.

T1027.016
Junk Code Insertion
MalwareNOOPLDR

NOOPLDR can insert junk code to obfuscate malicious payloads.

T1033
System Owner/User Discovery
GroupMirrorFace

MirrorFace has used Windows native tools to enumerate user information.

T1053.005
Scheduled Task
MalwareHiddenFace

HiddenFace has used scheduled tasks for execution and persistence.

T1055
Process Injection
MalwareNOOPLDR

NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe.

T1056.001
Keylogging
MalwareLODEINFO

LODEINFO can capture keystrokes on targeted systems.

T1059.003
Windows Command Shell
GroupMirrorFace

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.

T1070.004
File Deletion
MalwareNOOPLDR

NOOPLDR can delete a file containing configuration instructions after use.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1070.006
Timestomp
MalwareHiddenFace

HiddenFace can alter timestamps for directory content on targeted machines.

T1074.002
Remote Data Staging
GroupMirrorFace

MirrorFace has gathered data and files of interest on a single victim machine.

T1082
System Information Discovery
MalwareNOOPLDR

NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys.

T1082
System Information Discovery
MalwareHiddenFace

HiddenFace can enumerate the hostname and username of the compromised system.

T1082
System Information Discovery
GroupMirrorFace

MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.

T1083
File and Directory Discovery
GroupMirrorFace

MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.

T1087.002
Domain Account
GroupMirrorFace

MirrorFace has used native Windows tools to obtain domain user information.

T1090.001
Internal Proxy
MalwareHiddenFace

HiddenFace can act as an internal HTTP proxy within the targeted environment.

T1095
Non-Application Layer Protocol
MalwareHiddenFace

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1105
Ingress Tool Transfer
MalwareHiddenFace

HiddenFace can download files from the C2 to victim systems.

T1106
Native API
MalwareNOOPLDR

NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection.

T1112
Modify Registry
MalwareNOOPLDR

NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`.

T1140
Deobfuscate/Decode Files or Information
MalwareNOOPLDR

NOOPLDR can decrypt its payload prior to execution.

T1480
Execution Guardrails
MalwareHiddenFace

HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found.

T1482
Domain Trust Discovery
GroupMirrorFace

MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.

T1518.001
Security Software Discovery
MalwareHiddenFace

HiddenFace can identify processes identified with security applications and tooling.

T1547.001
Registry Run Keys / Startup Folder
MalwareLODEINFO

LODEINFO has used Registry run keys to set persistence.

T1552.006
Group Policy Preferences
MalwareMirrorStealer

MirrorStealer can target Group Policy Preferences for credentials.

T1555
Credentials from Password Stores
MalwareMirrorStealer

MirrorStealer has the ability to steal credentials from email clients.

T1555.003
Credentials from Web Browsers
MalwareMirrorStealer

MirrorStealer can steal credentials stored in browsers.

T1560.001
Archive via Utility
GroupMirrorFace

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

T1571
Non-Standard Port
MalwareHiddenFace

HiddenFace's passive mode listens on TCP 47000.

T1573.002
Asymmetric Cryptography
MalwareHiddenFace

HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1574.001
DLL
MalwareNOOPLDR

NOOPLDR can be executed via sideloading.

T1588.002
Tool
GroupMirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

T1686.003
Windows Host Firewall
MalwareHiddenFace

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.