← threatfilter.dev / all groups / MirrorFace
MirrorFace
Also known as: Earth Kasha
Overview
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 8 attributed custom malware families
TTPs — 43 techniques across 12 tactics
Reconnaissance
Initial Access
-
T1190Exploit Public-Facing Application -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1204.002Malicious File
Stealth
-
T1027.013Encrypted/Encoded File -
T1036.008Masquerade File Type -
T1070.004File Deletion -
T1221Template Injection -
T1574.001DLL -
T1684.001Impersonation
Defense Impairment
-
T1553.002Code Signing -
T1556.002Password Filter DLL -
T1685Disable or Modify Tools -
T1685.005Clear Windows Event Logs -
T1686.003Windows Host Firewall
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager -
T1003.003NTDS
Discovery
-
T1007System Service Discovery -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1057Process Discovery -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1087.002Domain Account -
T1482Domain Trust Discovery -
T1614.001System Language Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares
Collection
-
T1005Data from Local System -
T1074.002Remote Data Staging -
T1114.001Local Email Collection -
T1560.001Archive via Utility
Command and Control
-
T1071.002File Transfer Protocols -
T1090Proxy
Exfiltration
Tools & malware (16)
Net · Cobalt Strike · MirrorStealer · UPPERCUT · Nltest · BITSAdmin · Tasklist · ipconfig · LODEINFO · ROAMINGHOUSE · DOWNIISSA · nbtstat · HiddenFace · Ping · Wevtutil · NOOPLDR