Researchers detailed a long-running cyberespionage campaign using the LODEINFO fileless RAT to target organizations in Japan, including political entities, diplomacy, defense, media, academia, public institutions, and think tanks. The activity has been active since late 2019 and is widely associated with MirrorFace and possibly APT10-linked operators. Delivery has relied heavily on spearphishing with malicious Word documents, decoy files, and later Remote Template Injection, while many intrusions used DLL side-loading through legitimate executables to launch malware in memory and reduce forensic visibility.
Recent analysis shows LODEINFO continued to evolve through versions such as v0.6.6 to v0.7.3, adding anti-analysis and detection-evasion features including split Base64 shellcode, control-flow obfuscation, junk code, language checks, and changing API hash algorithms. The infection chain has used downloader shellcode to retrieve disguised payloads such as fake PEM files, decrypt components including Elze.exe and Frau.dll, and load the backdoor entirely in memory. The malware’s command set has expanded to support file theft, shellcode injection, screenshots, WMI execution, runas, keylogging, persistence, and even a ransom-related command, while infrastructure and document metadata overlaps have reinforced attribution links to Chinese state-backed espionage activity.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
As of January 2024, ITOCHU reported that LODEINFO was still under active development and identified v0.7.3 as the newest observed version. The analysis also detailed a downloader chain that retrieved a fake PEM file, decrypted embedded components including Elze.exe and Frau.dll, and loaded the backdoor via DLL side-loading.
The ITOCHU analysis states that multiple LODEINFO versions were found during 2023, showing continued active development. The report also notes strengthened obfuscation in versions v0.6.6, v0.6.8, and v0.6.9 using control-flow flattening and junk code.
ESET published reporting on MirrorFace's Operation LiberalFace targeting Japanese political entities. This is an external public reporting milestone relevant to the broader activity cluster referenced in the source set.
Researchers describe LODEINFO as a long-running cyberespionage campaign continuously observed since December 2019. The activity used spearphishing to target Japanese sectors including defense, diplomacy, politics, media, academia, and think tanks.
The JSAC/JPCERT report assesses with moderate confidence that a Chinese state-backed actor, possibly APT10, is behind LODEINFO. The attribution is supported in part by overlaps in decoy document metadata and tradecraft with older APT10-linked operations.
In v0.7.1, the language-check feature was removed and the malicious document filename changed from Japanese to English. The report assesses this version was likely used against non-Japanese language environments.
A language-check feature was implemented in the v0.7.0 malicious document to verify whether Microsoft Office was configured for Japanese. This represented a targeting and evasion refinement in the delivery stage.
LODEINFO v0.6.9 was observed using Remote Template Injection in Word documents. In this chain, the document fetched a malicious .dotm template from attacker infrastructure, including the referenced URL at 45.76.222[.]130/template.dotm, to execute VBA.
Versions v0.6.8 through v0.7.1 implemented a new infection flow embedding both 32-bit and 64-bit downloader shellcode in VBA macros. The macro checked system architecture, reconstructed split Base64-encoded shellcode, and injected the appropriate payload into memory.
The v0.6.5 branch introduced a pseudo-sleep function based on repeated SHA-256 calculations of random strings. It also added a new execution flow in which VBA-launched shellcode downloaded content from C2 and executed via msiexec.exe without DLL side-loading.
The v0.6.3 branch reduced the available command set from 21 commands to 11. Its execution flow used a three-component package of a legitimate executable, a DLL shellcode loader, and an encrypted blob, often delivered in SFX archives.
The v0.6.2 branch added version information to beacon payloads and updated the memory command to support 64-bit shellcode. Some samples also implemented locale checks that stalled execution outside selected locales such as ja-JP or en-US.
The v0.5.9 branch replaced CRC32-based API hashing with a JSHash-based algorithm combined with two-byte XOR. This altered a core anti-analysis and evasion mechanism.
The v0.5.6 branch encrypted former header fields in command-and-control traffic, added dummy Base64 data to beacon payloads, and obfuscated RAT command strings with unique two-byte XOR keys. These changes reduced the effectiveness of existing detection rules.
Later samples used K7SysMon.exe as another legitimate executable for DLL side-loading. This reflected an operational change in the malware's execution chain.
The v0.3.2 branch changed execution to DLL side-loading using a signed legitimate executable together with a malicious DLL loader. SfsDllSample.exe was then used continuously in part of the campaign.
In early campaigns, malicious VBA in phishing documents dropped a DLL and executed it via RunDll32.exe. This established the initial documented infection flow for LODEINFO.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.itochuci.co.jp
Open sourcewelivesecurity.com
Open sourcejsac.jpcert.or.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.