MirrorFace
Also known as: Earth Kasha
Overview
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
Naming & attribution
MirrorFace is tracked under 2 names across the industry. It uses 43 documented ATT&CK techniques — more than 78% of the 174 groups tracked here. Activity attributed since at least 2019.
| Name | First reported by |
|---|---|
| Earth Kasha | Trend Micro |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1556.002Password Filter DLL — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 8 attributed custom malware families
TTPs — 43 techniques across 12 tactics
Reconnaissance
Initial Access
-
T1190Exploit Public-Facing Application -
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1204.002Malicious File
Stealth
-
T1027.013Encrypted/Encoded File -
T1036.008Masquerade File Type -
T1070.004File Deletion -
T1221Template Injection -
T1574.001DLL -
T1684.001Impersonation
Defense Impairment
-
T1553.002Code Signing -
T1556.002Password Filter DLL -
T1685Disable or Modify Tools -
T1685.005Clear Windows Event Logs -
T1686.003Windows Host Firewall
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager -
T1003.003NTDS
Discovery
-
T1007System Service Discovery -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1057Process Discovery -
T1082System Information Discovery -
T1083File and Directory Discovery -
T1087.002Domain Account -
T1482Domain Trust Discovery -
T1614.001System Language Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares
Collection
-
T1005Data from Local System -
T1074.002Remote Data Staging -
T1114.001Local Email Collection -
T1560.001Archive via Utility
Command and Control
-
T1071.002File Transfer Protocols -
T1090Proxy
Exfiltration
Tools & malware (16)
Net · Cobalt Strike · MirrorStealer · UPPERCUT · Nltest · BITSAdmin · Tasklist · ipconfig · LODEINFO · ROAMINGHOUSE · DOWNIISSA · nbtstat · HiddenFace · Ping · Wevtutil · NOOPLDR