ATT&CKGroupsMirrorFace

MirrorFace

G1054

Threat group.View on attack.mitre.org

About this group

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.

Techniques used43

Procedure examples43

TechniqueProcedure example
T1003.001
LSASS Memory

MirrorFace has dumped LSASS memory for credential access.

T1003.002
Security Account Manager

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.003
NTDS

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1005
Data from Local System

MirrorFace gathered data and files of interest from victim's systems.

T1007
System Service Discovery

MirrorFace has used Tasklist for discovery post compromise.

T1016
System Network Configuration Discovery

MirrorFace has used ipconfig for reconnaissance.

T1018
Remote System Discovery

MirrorFace has used Ping for system discovery.

T1021.001
Remote Desktop Protocol

MirrorFace has used RDP to exfiltrate files of interest.

T1021.002
SMB/Windows Admin Shares

MirrorFace has used SMB to copy malware between systems in compromised environments.

T1027.013
Encrypted/Encoded File

MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.

T1033
System Owner/User Discovery

MirrorFace has used Windows native tools to enumerate user information.

T1036.008
Masquerade File Type

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.

T1047
Windows Management Instrumentation

MirrorFace has leveraged WMIC on targeted systems post compromise.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.

T1057
Process Discovery

MirrorFace has used Tasklist on compromised hosts for discovery.

View all 43 procedure examples

Software16

Campaigns1

References6

  1. ESET MirrorFace DEC 2022 Open source
    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.
  2. JPCERT MirrorFace JUL 2024 Open source
    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
  3. Kaspersky LODEINFO OCT 2022 Open source
    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.
  4. Kaspersky LODEINFO Part II OCT 2022 Open source
    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.
  5. Trend Micro Earth Kasha NOV 2024 Open source
    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.
  6. Trend Micro Earth Kasha Updates APR 2025 Open source
    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.