In this session, I delve into my extensive research on a sophisticated APT campaign utilizing the elusive LODEINFO backdoor. Despite limited open-source information, LODEINFO’s intricate modules feature numerous anti-reversing measures. Maintaining robust analysis capabilities is vital in fulfilling our CSIRT responsibilities and safeguarding our organization.
This presentation unveils the outcomes of a comprehensive analysis of LODEINFO’s latest version, v0.7.1. Gain insights into its backdoor modules, propagation methods, and underlying infrastructure. Join me in unraveling the complexities of this potent threat.
#SAS2023 #Lodeinfo #Kaspersky