Chinese Hackers Using New Stealthy Infection Chain to Deploy LODEINFO Malware

Teilen:

The Chinese state-sponsored threat actor known as Stone Panda has been observed employing a new stealthy infection chain in its attacks aimed at Japanese entities.

Targets include media, diplomatic, governmental and public sector organizations and think-tanks in Japan, according to twin reports published by Kaspersky.

Stone Panda, also called APT10, Bronze Riverside, Cicada, and Potassium, is a cyber espionage group known for its intrusions against organizations identified as strategically significant to China. The threat actor is believed to have been active since at least 2009.

The group has also been linked to attacks using malware families like SigLoader, SodaMaster, and a web shell called Jackpot against multiple Japanese domestic organizations since April 2021, per cybersecurity firm Trend Micro, which is tracking the group under the name Earth Tengshe.

The latest set of attacks, observed between March and June 2022, involve the use of a bogus Microsoft Word file and a self-extracting archive (SFX) file in RAR format propagated via spear-phishing emails, leading to the execution of a backdoor called LODEINFO.

While the maldoc requires users to enable macros to activate the killchain, the June 2022 campaign was found to drop this method in favor of an SFX file that, when executed, displays a harmless decoy Word document to conceal the malicious activities.

The macro, once enabled, drops a ZIP archive containing two files, one of which (“NRTOLF.exe”) is a legitimate executable from the K7Security Suite software that’s subsequently used to load a rogue DLL (“K7SysMn1.dll”) via DLL side-loading.

The abuse of the security application aside, Kaspersky said it also discovered in June 2022 another initial infection method wherein a password-protected Microsoft Word file acted as a conduit to deliver a fileless downloader dubbed DOWNIISSA upon enabling macros.

coding blue green 1

“The embedded macro generates the DOWNIISSA shellcode and injects it in the current process (WINWORD.exe),” the Russian cybersecurity company said.

DOWNIISSA is configured to communicate with a hard-coded remote server, using it to retrieve an encrypted BLOB payload of LODEINFO, a backdoor capable of executing arbitrary shellcode, take screenshots, and exfiltrate files back to the server.

The malware, first seen in 2019, has undergone numerous improvements, with Kaspersky identified six different versions in March, April, June, and September 2022.

The changes include enhanced evasion techniques to fly under the radar, halting execution on machines with the locale “en_US,” revising the list of supported commands, and extending support for Intel 64-bit architecture.

“LODEINFO malware is updated very frequently and continues to actively target Japanese organizations,” the researchers concluded.

“The updated TTPs and improvements in LODEINFO and related malware […] indicate that the attacker is particularly focused on making detection, analysis and investigation harder for security researchers.”

https://thehackernews.com/2022/11/chinese-hackers-using-new-stealthy.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:30 am, Juli 8, 2025
Wetter-Symbol 16°C
L: 14° | H: 17°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 66 %
Druck: 1014 mb
Wind: 8 mph WNW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 45%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:53 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 17°°C 0.34 mm 34% 11 mph 71 % 1019 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 26°°C 0.2 mm 20% 7 mph 65 % 1022 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
19° | 31°°C 0 mm 0% 6 mph 74 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
20° | 31°°C 0 mm 0% 10 mph 66 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 29°°C 0 mm 0% 10 mph 70 % 1020 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
14° | 16°°C 0.2 mm 20% 11 mph 66 % 1014 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
12° | 14°°C 0.34 mm 34% 11 mph 71 % 1014 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 10 mph 68 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 47 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 33 % 1018 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 7 mph 29 % 1017 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 7 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 41 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,221.93
-0.89%
Ethereum(ETH)
€2,166.08
-1.07%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.94
0.38%
Solana(SOL)
€126.73
-2.12%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.142610
-2.63%
Shiba Inu(SHIB)
€0.000010
-1.71%
Pepe(PEPE)
€0.000009
-2.00%
Nach oben scrollen