LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S9020: LODEINFO

LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.CitationKaspersky LODEINFO OCT 2022CitationITOCHU LODEINFO JAN 2024CitationESET MirrorFace DEC 2022

EnterpriseS9020MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

LODEINFO is a Windows fileless backdoor associated in ATT&CK with MirrorFace use and reporting focused on Japanese media, diplomatic, governmental, and public-sector targets. Its practical significance is not just malware presence: the mapped behaviors cover stealth, discovery, collection, credential capture, tool transfer, command-and-control, and exfiltration over C2, which means defenders should validate whether endpoint, network, and investigation telemetry can reconstruct activity even when few traditional files are left behind.

Executive priority

Treat LODEINFO as a readiness test for high-consequence espionage-style intrusions against Windows environments. Priority questions are: can the organization detect fileless or memory-resident activity, WMI abuse, process injection, local discovery, data staging, and exfiltration over C2; can incident responders scope affected hosts without relying only on recovered malware files; and can security teams produce audit-quality evidence that monitoring and egress controls cover sensitive business, government, diplomatic, or public-sector workflows where relevant.

Technical view

ATT&CK provides no official detection text for S9020, so coverage should be validated from the related techniques. On Windows, focus on behavioral chains: WMI execution, Native API use, dynamic API resolution, process injection, obfuscated/encoded/compressed content, junk code or junk C2 data, host and network discovery, file and directory enumeration, local data staging, keylogging or screen capture behavior, file deletion, ingress tool transfer, and exfiltration over the existing C2 channel. Detection engineering should emphasize correlation across endpoint memory/process telemetry, Windows management activity, file-system activity, and network egress rather than single static indicators.

Likely telemetry

  • EDR or equivalent endpoint telemetry for process creation, process injection, memory allocation patterns, module/API usage, and suspicious child-process relationships
  • Windows Management Instrumentation activity, including WMI process execution and remote/local management events
  • File-system telemetry for enumeration, staging directories, compressed or encoded artifacts, tool transfer, and deletion of recently created files
  • Network telemetry from proxy, firewall, DNS, TLS metadata, and egress monitoring for unusual C2-like sessions, data transfer, and protocol content anomalies such as junk data where observable
  • Host discovery evidence such as network configuration queries, process discovery, system information discovery, user discovery, remote system discovery, and system time checks

Detection direction

  • Build detections around sequences, not only malware names: discovery followed by staging, C2 communication, tool transfer, collection, and exfiltration is more decision-useful than a single weak signal.
  • Validate WMI monitoring depth because T1047 is explicitly mapped and WMI often overlaps with legitimate administration; tune by administrator context, destination, command content, and unusual timing.
  • Review endpoint capability for fileless and memory behaviors, including process injection and dynamic API resolution; static file scanning alone is unlikely to be sufficient for a fileless backdoor profile.
  • Use network analytics to look for persistent or unusual outbound channels and exfiltration over the same channel used for command-and-control; account for the mapped use of junk data that may reduce simple pattern-matching value.
  • Treat obfuscation, compression, encoded files, and file deletion as supporting evidence. These behaviors can be legitimate, so prioritize correlation with execution, discovery, staging, or outbound transfer.

Mitigation priorities

  • Prioritize visibility first: ensure Windows endpoint, WMI, file-system, and network egress logs are collected, retained, and searchable for incident response scoping.
  • Harden and monitor administrative execution paths such as WMI, limiting use to expected administrators and systems where operationally feasible.
  • Strengthen egress control and monitoring so unknown outbound command-and-control or exfiltration channels are more likely to be blocked, alerted, or investigated.
  • Reduce collection and credential risk by applying least privilege, protecting sensitive local data, and monitoring access to high-value files and user input/screen capture behaviors where supported.
  • Prepare IR playbooks for fileless backdoor investigations, including memory acquisition, timeline reconstruction, C2 scoping, staged-data searches, and review of file deletion activity.
Additional notes and limits

The strongest defensive value comes from the relationship set: LODEINFO is mapped to multiple discovery, stealth, collection, execution, C2, exfiltration, and cleanup techniques. The MirrorFace relationship and official description provide threat-intelligence context, especially around Japanese public-sector and related organizations, but local risk should be determined by the organization’s geography, mission, exposed Windows estate, and data sensitivity.

MITRE does not provide official detection text, aliases, labels, or malware tactics for this object in the supplied fields. The object platform is Windows, while several related techniques list broader platforms; this take therefore focuses on Windows-relevant validation. No claim is made here about current activity, customer exposure, guaranteed detection, or exploitation beyond the supplied ATT&CK description and relationships.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

LODEINFO

LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.CitationKaspersky LODEINFO OCT 2022CitationITOCHU LODEINFO JAN 2024CitationESET MirrorFace DEC 2022

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
e2cf2915db8ef857...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.