Description
LODEINFO is a fileless backdoor first identified in 2020 that actors including MirrorFace have used primarily against media, diplomatic, governmental, and public sector organizations in Japan.
Stats
- First seen
- March 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
32 techniques across 10 tactics.
TA0002 Execution
TA0005 Stealth
TA0006 Credential Access
- T1539Steal Web Session Cookie
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
TA0040 Impact
- T1486Data Encrypted for Impact
Associated groups
Alert name variants
| Alert Name |
|---|
| Script-Macro.Trojan.Lodeinfo |
| Win32.Backdoor.Lodeinfo |
| Win32.Trojan.Lodeinfo |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Win.Trojan.LODEINFO outbound connection |