ATT&CKReferencesESET MirrorFace DEC 2022

ESET MirrorFace DEC 2022

Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples32

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareLODEINFO

LODEINFO can append C2 communication with randomly generated junk data.

T1005
Data from Local System
MalwareLODEINFO

LODEINFO can upload files from infected hosts to the C2.

T1018
Remote System Discovery
MalwareLODEINFO

LODEINFO can run `net view` and `net view /domain` for network discovery.

T1041
Exfiltration Over C2 Channel
MalwareLODEINFO

LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server.

T1055
Process Injection
MalwareLODEINFO

LODEINFO can inject shellcode into the memory of compromised hosts.

T1056.001
Keylogging
MalwareLODEINFO

LODEINFO can capture keystrokes on targeted systems.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1071.002
File Transfer Protocols
GroupMirrorFace

MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.

T1074.001
Local Data Staging
MalwareLODEINFO

LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder.

T1074.001
Local Data Staging
MalwareMirrorStealer

MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`.

T1083
File and Directory Discovery
MalwareLODEINFO

LODEINFO has the ability to designate specific files and folders to encryption.

T1083
File and Directory Discovery
GroupMirrorFace

MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.

T1105
Ingress Tool Transfer
MalwareLODEINFO

LODEINFO has the ability to download additional files from the C2.

T1113
Screen Capture
MalwareLODEINFO

LODEINFO has the ability to take screenshots.

T1114.001
Local Email Collection
GroupMirrorFace

MirrorFace has exfiltrated stored emails from compromised hosts.

T1204.002
Malicious File
GroupMirrorFace

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.

T1204.002
Malicious File
MalwareLODEINFO

LODEINFO has been executed via victims opening malicious email attachments.

T1486
Data Encrypted for Impact
MalwareLODEINFO

LODEINFO can incorporate a ransom command to encrypt specified files and folders.

T1539
Steal Web Session Cookie
MalwareLODEINFO

LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies.

T1547.001
Registry Run Keys / Startup Folder
MalwareLODEINFO

LODEINFO has used Registry run keys to set persistence.

T1553.002
Code Signing
GroupMirrorFace

MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.

T1555
Credentials from Password Stores
MalwareMirrorStealer

MirrorStealer has the ability to steal credentials from email clients.

T1555.003
Credentials from Web Browsers
MalwareMirrorStealer

MirrorStealer can steal credentials stored in browsers.

T1556.002
Password Filter DLL
GroupMirrorFace

MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes.

T1560.001
Archive via Utility
GroupMirrorFace

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.

T1566.001
Spearphishing Attachment
MalwareLODEINFO

LODEINFO has been distributed to targeted victims via malicious email attachments.

T1566.001
Spearphishing Attachment
GroupMirrorFace

MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.

T1574.001
DLL
GroupMirrorFace

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.

T1587.001
Malware
GroupMirrorFace

MirrorFace has created and continued to develop custom strains of malware including LODEINFO.

T1588.002
Tool
GroupMirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

T1591
Gather Victim Org Information
GroupMirrorFace

MirrorFace has placed specific content in phishing emails to target members of particular political parties.

T1684.001
Impersonation
GroupMirrorFace

MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.