logo

LODEINFO Fileless Malware Evolves with Anti-Analysis and Remote Code Tricks

ID: ccdf8dbc-44b1-5ea1-b094-60f915657d26

STIX ID: report--ccdf8dbc-44b1-5ea1-b094-60f915657d26

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-01-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers at ITOCHU Cyber & Intelligence have identified updated versions of the LODEINFO fileless backdoor (up to v0.7.3) used by the Chinese nation-state actor Stone Panda (APT10). The report highlights spear-phishing delivery via malicious Word macros and remote template injection, a fileless shellcode downloader that can load payloads directly into memory (including a PEM-masquerading intermediate), new anti-analysis techniques and language checks observed in different versions, active use against Japanese targets in 2023–2024, and recommends endpoint memory-scanning defenses to detect the in-memory malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.