ATT&CKReferencesITOCHU LODEINFO JAN 2024

ITOCHU LODEINFO JAN 2024

ITOCHU. (2024, January 24). The Endless Struggle Against APT10: Insights from LODEINFO v0.6.6 - v0.7.3 Analysis. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareLODEINFO

LODEINFO can upload files from infected hosts to the C2.

T1027
Obfuscated Files or Information
MalwareLODEINFO

LODEINFO has used control flow flattening to obfuscate code.

T1027.013
Encrypted/Encoded File
MalwareLODEINFO

The LODEINFO loader module contains XOR-encrypted shellcode.

T1027.013
Encrypted/Encoded File
GroupMirrorFace

MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.

T1027.016
Junk Code Insertion
MalwareLODEINFO

LODEINFO has inserted junk code to obstruct code analysis.

T1033
System Owner/User Discovery
MalwareLODEINFO

LODEINFO can identify the associated username on targeted machines.

T1036.008
Masquerade File Type
GroupMirrorFace

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.

T1047
Windows Management Instrumentation
MalwareLODEINFO

LODEINFO can execute commands with WMI.

T1055
Process Injection
MalwareLODEINFO

LODEINFO can inject shellcode into the memory of compromised hosts.

T1056.001
Keylogging
MalwareLODEINFO

LODEINFO can capture keystrokes on targeted systems.

T1057
Process Discovery
MalwareLODEINFO

LODEINFO can kill a process using specific process ID.

T1059.005
Visual Basic
GroupMirrorFace

MirrorFace has used remote templates with VBA code in malware infection chains.

T1070.004
File Deletion
MalwareLODEINFO

LODEINFO can delete files to remove traces of activity from victim systems.

T1082
System Information Discovery
MalwareLODEINFO

LODEINFO can disover machine information including OS architecture, the ANSI code page (ACP) identifier, and hostname.

T1082
System Information Discovery
GroupMirrorFace

MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.

T1083
File and Directory Discovery
MalwareLODEINFO

LODEINFO has the ability to designate specific files and folders to encryption.

T1105
Ingress Tool Transfer
MalwareLODEINFO

LODEINFO has the ability to download additional files from the C2.

T1113
Screen Capture
MalwareLODEINFO

LODEINFO has the ability to take screenshots.

T1204.002
Malicious File
GroupMirrorFace

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.

T1204.002
Malicious File
MalwareLODEINFO

LODEINFO has been executed via victims opening malicious email attachments.

T1221
Template Injection
GroupMirrorFace

MirrorFace has used remote template injection to retrieve malicious payloads from the C2.

T1486
Data Encrypted for Impact
MalwareLODEINFO

LODEINFO can incorporate a ransom command to encrypt specified files and folders.

T1566.001
Spearphishing Attachment
GroupMirrorFace

MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1614.001
System Language Discovery
GroupMirrorFace

MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.