LODEINFO Fileless Malware Evolves with Anti-Analysis and Remote Code Tricks
ID: ccdf8dbc-44b1-5ea1-b094-60f915657d26
STIX ID: report--ccdf8dbc-44b1-5ea1-b094-60f915657d26
Feed Name: The Hacker News
Researchers at ITOCHU Cyber & Intelligence have identified updated versions of the LODEINFO fileless backdoor (up to v0.7.3) used by the Chinese nation-state actor Stone Panda (APT10). The report highlights spear-phishing delivery via malicious Word macros and remote template injection, a fileless shellcode downloader that can load payloads directly into memory (including a PEM-masquerading intermediate), new anti-analysis techniques and language checks observed in different versions, active use against Japanese targets in 2023–2024, and recommends endpoint memory-scanning defenses to detect the in-memory malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
