APT10__2024__The_Endless_Struggle_Against_APT10_Insights_from_LODEINFO_v0.6.6_-_v0.7.3_Analysis_-_Researcher_Blog_-_ITOCHU_Cyber_Intelligence_Inc.pdf
ID: 38fa910a-bdb1-4ffe-99bc-1049c6fbeca1
STIX ID: report--38fa910a-bdb1-4ffe-99bc-1049c6fbeca1
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2024-01-30
Last Modified Date: 2024-01-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
LODEINFO is an actively developed, fileless backdoor observed from 2022–2024 that infects targets via spear‑phishing Word documents (including Remote Template Injection), uses 32/64‑bit downloader shellcode to fetch and decrypt a fake PEM containing staged components (legitimate EXE + malicious DLL) and loads an in‑memory backdoor; the report details version differences up to v0.7.3, advanced anti‑analysis and obfuscation techniques, available IoCs (hashes and C2 IPs), and links to APT activity consistent with prior APT10 reporting.
