NOOPLDR

S9025

Malware.View on attack.mitre.org

About this malware

NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027
Obfuscated Files or Information

NOOPLDR can use control flow flattening to help hide malicious code.

T1027.013
Encrypted/Encoded File

The NOOPLDR payload is encrypted with AES256-CBC.

T1027.016
Junk Code Insertion

NOOPLDR can insert junk code to obfuscate malicious payloads.

T1055
Process Injection

NOOPLDR can inject decrypted payloads into processes including wuauclt.exe., rdrleakdiag.exe, and tabcal.exe.

T1070.004
File Deletion

NOOPLDR can delete a file containing configuration instructions after use.

T1082
System Information Discovery

NOOPLDR can discover the device ID and hostname from the targeted machine to use for encryption keys.

T1106
Native API

NOOPLDR can use native APIs `NtProtectVirtualMemory`, `NtWriteVirtualMemory`, and `NtCreateThreadEx` to aid process injection.

T1112
Modify Registry

NOOPLDR can store its payload in the Registry using a random hex string in `HKCU\SOFTWARE\Microsoft\COM3`.

T1127.001
MSBuild

NOOPLDR can be executed via MSBuild.

T1140
Deobfuscate/Decode Files or Information

NOOPLDR can decrypt its payload prior to execution.

T1564
Hide Artifacts

NOOPLDR can hide services used to aid execution.

T1574.001
DLL

NOOPLDR can be executed via sideloading.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Earth Kasha NOV 2024 Open source
    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.