DOWNIISSA

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[DOWNIISSA](https://attack.mitre.org/software/S9021) is a shellcode downloader that has been used by [MirrorFace](https://attack.mitre.org/groups/G1054) since at least 2022 to deploy payloads, including the [LODEINFO](https://attack.mitre.org/software/S9020) backdoor.(Citation: Kaspersky LODEINFO OCT 2022)

Associated Techniques (7)
ID ATT&CK Tactics
T1027.013 Encrypted/Encoded File -
T1055 Process Injection -
T1070.004 File Deletion -
T1105 Ingress Tool Transfer -
T1106 Native API -
T1140 Deobfuscate/Decode Files or Information -
T1218.007 Msiexec -
Used by Actors (1)
Metadata
ID: 164743
Created: 28/04/2026 16:00
Updated: 01/05/2026 04:00