LODEINFO is a Windows backdoor used in cyber-espionage operations attributed to MirrorFace, also tracked as Earth Kasha, a China-aligned intrusion set associated with the broader APT10 umbrella. Active since at least 2019 and publicly identified in 2020, it has been a primary implant in campaigns targeting organizations connected to Japan, including government, diplomatic, media, think tank, academic, public-sector, defense, high-technology, and manufacturing entities. Later reporting also tied its use to operations affecting Taiwan and India.
LODEINFO is notable for fileless or memory-resident execution patterns and for frequent iterative development. Observed delivery chains include spearphishing documents with malicious macros, self-extracting archives, and DLL sideloading using legitimate signed executables. Related campaigns have also involved exploitation of public-facing enterprise applications such as SSL-VPN and file-storage services to gain access before deploying the malware. Since earlier versions, operators have also shifted portions of execution toward living-off-the-land techniques.
Functionally, LODEINFO operates as a backdoor for remote command execution and follow-on payload delivery. Documented capabilities include host beaconing, encrypted command-and-control communications, execution of shellcode in memory, process injection, and network discovery using native commands. Some versions supported keylogging, while later variants streamlined or removed parts of the command set. The malware has also been observed collecting browser session material such as web cookies and staging stolen data locally prior to exfiltration. Its operators use it as part of broader espionage workflows focused on collecting documents and other information of intelligence value.
The malware incorporates substantial defense-evasion and anti-analysis measures. Reported versions introduced obfuscated command identifiers, custom API hashing, layered encryption for C2 traffic, junk data appended to beacon traffic, locale-based execution checks intended to avoid analysis environments, and support for both 32-bit and 64-bit shellcode injection. Its communication patterns and loader chains have been repeatedly revised, indicating sustained maintenance and adaptation in response to defensive scrutiny.
LODEINFO is strongly associated with MirrorFace and has been described as distinctive to that actor’s operations, although some reporting places the group within or adjacent to APT10. It has served as a long-running espionage implant in campaigns centered on East Asian strategic and political interests.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Alongside the new target, the group revived ANEL (also called UPPERCUT), an APT10 backdoor that had been dormant since roughly 2018-2019, moving away from LODEINFO, its previous mainstay implant.
Trend Micro tracks Earth Kasha as related to the “APT10 Umbrella” but not necessarily identical to APT10; its 2024 reporting noted LODEINFO use against Japan, Taiwan, and India, including exploitation of public-facing applications such as SSL-VPN and file-storage services.
Trend Micro tracks Earth Kasha as related to the “APT10 Umbrella” but not necessarily identical to APT10; its 2024 reporting noted LODEINFO use against Japan, Taiwan, and India, including exploitation of public-facing applications such as SSL-VPN and file-storage services.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or batch files in the Windows Startup folder.
During the memory injection process... the malware checks the first byte of the second stage shellcode to determine the shellcode architecture... it uses the basic Windows APIs such as VirtualAllocEx(), WriteProcessMemory() and CreateRemoteThread() for memory injection of the 32-bit shellcode and NtAllocateVirtualMemory(), NtWriteVirtualMemory() and RtlCreateUserThread() for supporting the memory injection of the 64-bit shellcode.
The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or batch files in the Windows Startup folder.
This LODEINFO v0.5.6 shellcode extracted from a loader module demonstrates several enhanced evasion techniques... The beacon also contains a hardcoded key... randomly generated junk data is appended to the end of the data, possibly to evade beaconing detection based on packet size.
The attackers exploited the name of a well-known Japanese politician... The file name and the decoy document suggest the target was the Japanese ruling party or a related organization.
During the memory injection process... the malware checks the first byte of the second stage shellcode to determine the shellcode architecture... it uses the basic Windows APIs such as VirtualAllocEx(), WriteProcessMemory() and CreateRemoteThread() for memory injection of the 32-bit shellcode and NtAllocateVirtualMemory(), NtWriteVirtualMemory() and RtlCreateUserThread() for supporting the memory injection of the 64-bit shellcode.
For the final stage of the infection, DOWNIISSA creates an instance of msiexec.exe and injects the LODEINFO backdoor shellcode in the memory of the process.
In LODEINFO v0.6.2 and later versions, the shellcode has a new feature that looks for the “en_US” locale on the victim’s machine in a recursive function and halts execution if that locale is found.
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
After infecting the target machine, the LODEINFO backdoor beacons out machine information to the C2, such as current time, ANSI code page (ACP) identifier, MAC address and hostname.
keylog Check for Japanese keyboard layout. Save keystrokes, datetime and active window name. Uses 1-byte XOR encryption and a file %temp%\%hostname%.tmp.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previous mainstay implant used by MirrorFace before the recent shift back to ANEL.
Backdoor/tool used in newer APT10-umbrella activity, particularly Earth Kasha campaigns targeting Japan, Taiwan, and India.
Backdoor used via DLL sideloading in targeted cyber-espionage attacks.
Custom malware developed and used by MirrorFace.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.