Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareLODEINFO | LODEINFO can append C2 communication with randomly generated junk data. |
| T1005 Data from Local System |
MalwareLODEINFO | LODEINFO can upload files from infected hosts to the C2. |
| T1018 Remote System Discovery |
MalwareLODEINFO | LODEINFO can run `net view` and `net view /domain` for network discovery. |
| T1041 Exfiltration Over C2 Channel |
MalwareLODEINFO | LODEINFO can exfiltrate collected credentials and browser cookies to the C2 server. |
| T1055 Process Injection |
MalwareLODEINFO | LODEINFO can inject shellcode into the memory of compromised hosts. |
| T1056.001 Keylogging |
MalwareLODEINFO | LODEINFO can capture keystrokes on targeted systems. |
| T1070.004 File Deletion |
GroupMirrorFace | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment. |
| T1071.002 File Transfer Protocols |
GroupMirrorFace | MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer. |
| T1074.001 Local Data Staging |
MalwareLODEINFO | LODEINFO has collected stolen web cookies locally in the `%TEMP%` folder. |
| T1074.001 Local Data Staging |
MalwareMirrorStealer | MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`. |
| T1083 File and Directory Discovery |
MalwareLODEINFO | LODEINFO has the ability to designate specific files and folders to encryption. |
| T1083 File and Directory Discovery |
GroupMirrorFace | MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions. |
| T1105 Ingress Tool Transfer |
MalwareLODEINFO | LODEINFO has the ability to download additional files from the C2. |
| T1113 Screen Capture |
MalwareLODEINFO | LODEINFO has the ability to take screenshots. |
| T1114.001 Local Email Collection |
GroupMirrorFace | MirrorFace has exfiltrated stored emails from compromised hosts. |
| T1204.002 Malicious File |
GroupMirrorFace | MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution. |
| T1204.002 Malicious File |
MalwareLODEINFO | LODEINFO has been executed via victims opening malicious email attachments. |
| T1486 Data Encrypted for Impact |
MalwareLODEINFO | LODEINFO can incorporate a ransom command to encrypt specified files and folders. |
| T1539 Steal Web Session Cookie |
MalwareLODEINFO | LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLODEINFO | LODEINFO has used Registry run keys to set persistence. |
| T1553.002 Code Signing |
GroupMirrorFace | MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed. |
| T1555 Credentials from Password Stores |
MalwareMirrorStealer | MirrorStealer has the ability to steal credentials from email clients. |
| T1555.003 Credentials from Web Browsers |
MalwareMirrorStealer | MirrorStealer can steal credentials stored in browsers. |
| T1556.002 Password Filter DLL |
GroupMirrorFace | MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes. |
| T1560.001 Archive via Utility |
GroupMirrorFace | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
MalwareLODEINFO | LODEINFO has been distributed to targeted victims via malicious email attachments. |
| T1566.001 Spearphishing Attachment |
GroupMirrorFace | MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads. |
| T1574.001 DLL |
GroupMirrorFace | MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading. |
| T1587.001 Malware |
GroupMirrorFace | MirrorFace has created and continued to develop custom strains of malware including LODEINFO. |
| T1588.002 Tool |
GroupMirrorFace | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike. |
| T1591 Gather Victim Org Information |
GroupMirrorFace | MirrorFace has placed specific content in phishing emails to target members of particular political parties. |
| T1684.001 Impersonation |
GroupMirrorFace | MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.