ATT&CKReferencesJPCERT MirrorFace JUL 2024

JPCERT MirrorFace JUL 2024

Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples37

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMirrorFace

MirrorFace has dumped LSASS memory for credential access.

T1003.002
Security Account Manager
GroupMirrorFace

MirrorFace has used vssadmin to copy registry hives including SAM.

T1003.003
NTDS
GroupMirrorFace

MirrorFace has dumped NTDS.dit through volume shadow copies.

T1005
Data from Local System
MalwareHiddenFace

HiddenFace can upload files from the victim machine to C2 nodes.

T1007
System Service Discovery
GroupMirrorFace

MirrorFace has used Tasklist for discovery post compromise.

T1016
System Network Configuration Discovery
GroupMirrorFace

MirrorFace has used ipconfig for reconnaissance.

T1018
Remote System Discovery
GroupMirrorFace

MirrorFace has used Ping for system discovery.

T1021.002
SMB/Windows Admin Shares
GroupMirrorFace

MirrorFace has used SMB to copy malware between systems in compromised environments.

T1027
Obfuscated Files or Information
MalwareNOOPLDR

NOOPLDR can use control flow flattening to help hide malicious code.

T1027.013
Encrypted/Encoded File
MalwareHiddenFace

HiddenFace has encrypted its payload with AES.

T1027.016
Junk Code Insertion
MalwareNOOPLDR

NOOPLDR can insert junk code to obfuscate malicious payloads.

T1047
Windows Management Instrumentation
GroupMirrorFace

MirrorFace has leveraged WMIC on targeted systems post compromise.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupMirrorFace

MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.

T1055
Process Injection
MalwareHiddenFace

HiddenFace can inject code directly into legitimate applications.

T1057
Process Discovery
GroupMirrorFace

MirrorFace has used Tasklist on compromised hosts for discovery.

T1059.003
Windows Command Shell
GroupMirrorFace

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1070.006
Timestomp
MalwareHiddenFace

HiddenFace can alter timestamps for directory content on targeted machines.

T1082
System Information Discovery
GroupMirrorFace

MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.

T1082
System Information Discovery
MalwareHiddenFace

HiddenFace can enumerate the hostname and username of the compromised system.

T1083
File and Directory Discovery
GroupMirrorFace

MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.

T1090
Proxy
GroupMirrorFace

MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.

T1095
Non-Application Layer Protocol
MalwareHiddenFace

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1105
Ingress Tool Transfer
MalwareHiddenFace

HiddenFace can download files from the C2 to victim systems.

T1112
Modify Registry
MalwareHiddenFace

HiddenFace can store its configuration file in the Registry.

T1127.001
MSBuild
MalwareNOOPLDR

NOOPLDR can be executed via MSBuild.

T1140
Deobfuscate/Decode Files or Information
MalwareHiddenFace

HiddenFace has the ability to decrypt its payload prior to execution.

T1190
Exploit Public-Facing Application
GroupMirrorFace

MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access.

T1560.001
Archive via Utility
GroupMirrorFace

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.

T1564
Hide Artifacts
MalwareNOOPLDR

NOOPLDR can hide services used to aid execution.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

T1571
Non-Standard Port
MalwareHiddenFace

HiddenFace's passive mode listens on TCP 47000.

T1574.001
DLL
MalwareNOOPLDR

NOOPLDR can be executed via sideloading.

T1588.002
Tool
GroupMirrorFace

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.

T1685
Disable or Modify Tools
GroupMirrorFace

MirrorFace has disabled Windows Defender in compromised environments.

T1685.005
Clear Windows Event Logs
GroupMirrorFace

MirrorFace has deleted Windows event logs.

T1686.003
Windows Host Firewall
GroupMirrorFace

MirrorFace can modify the system firewall to allow communication to certain ports.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.