Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMirrorFace | MirrorFace has dumped LSASS memory for credential access. |
| T1003.002 Security Account Manager |
GroupMirrorFace | MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.003 NTDS |
GroupMirrorFace | MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1005 Data from Local System |
MalwareHiddenFace | HiddenFace can upload files from the victim machine to C2 nodes. |
| T1007 System Service Discovery |
GroupMirrorFace | MirrorFace has used Tasklist for discovery post compromise. |
| T1016 System Network Configuration Discovery |
GroupMirrorFace | MirrorFace has used ipconfig for reconnaissance. |
| T1018 Remote System Discovery |
GroupMirrorFace | MirrorFace has used Ping for system discovery. |
| T1021.002 SMB/Windows Admin Shares |
GroupMirrorFace | MirrorFace has used SMB to copy malware between systems in compromised environments. |
| T1027 Obfuscated Files or Information |
MalwareNOOPLDR | NOOPLDR can use control flow flattening to help hide malicious code. |
| T1027.013 Encrypted/Encoded File |
MalwareHiddenFace | HiddenFace has encrypted its payload with AES. |
| T1027.016 Junk Code Insertion |
MalwareNOOPLDR | NOOPLDR can insert junk code to obfuscate malicious payloads. |
| T1047 Windows Management Instrumentation |
GroupMirrorFace | MirrorFace has leveraged WMIC on targeted systems post compromise. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
GroupMirrorFace | MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration. |
| T1055 Process Injection |
MalwareHiddenFace | HiddenFace can inject code directly into legitimate applications. |
| T1057 Process Discovery |
GroupMirrorFace | MirrorFace has used Tasklist on compromised hosts for discovery. |
| T1059.003 Windows Command Shell |
GroupMirrorFace | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation. |
| T1070.004 File Deletion |
GroupMirrorFace | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment. |
| T1070.006 Timestomp |
MalwareHiddenFace | HiddenFace can alter timestamps for directory content on targeted machines. |
| T1082 System Information Discovery |
GroupMirrorFace | MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery. |
| T1082 System Information Discovery |
MalwareHiddenFace | HiddenFace can enumerate the hostname and username of the compromised system. |
| T1083 File and Directory Discovery |
GroupMirrorFace | MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions. |
| T1090 Proxy |
GroupMirrorFace | MirrorFace has used the GO Simple Tunnel (GOST) proxy tool. |
| T1095 Non-Application Layer Protocol |
MalwareHiddenFace | HiddenFace can use a custom TCP protocol over Port 443 for C2. |
| T1105 Ingress Tool Transfer |
MalwareHiddenFace | HiddenFace can download files from the C2 to victim systems. |
| T1112 Modify Registry |
MalwareHiddenFace | HiddenFace can store its configuration file in the Registry. |
| T1127.001 MSBuild |
MalwareNOOPLDR | NOOPLDR can be executed via MSBuild. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareHiddenFace | HiddenFace has the ability to decrypt its payload prior to execution. |
| T1190 Exploit Public-Facing Application |
GroupMirrorFace | MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access. |
| T1560.001 Archive via Utility |
GroupMirrorFace | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration. |
| T1564 Hide Artifacts |
MalwareNOOPLDR | NOOPLDR can hide services used to aid execution. |
| T1568.002 Domain Generation Algorithms |
MalwareHiddenFace | HiddenFace has used dynamic domain generation algorithms in C2. |
| T1571 Non-Standard Port |
MalwareHiddenFace | HiddenFace's passive mode listens on TCP 47000. |
| T1574.001 DLL |
MalwareNOOPLDR | NOOPLDR can be executed via sideloading. |
| T1588.002 Tool |
GroupMirrorFace | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike. |
| T1685 Disable or Modify Tools |
GroupMirrorFace | MirrorFace has disabled Windows Defender in compromised environments. |
| T1685.005 Clear Windows Event Logs |
GroupMirrorFace | MirrorFace has deleted Windows event logs. |
| T1686.003 Windows Host Firewall |
GroupMirrorFace | MirrorFace can modify the system firewall to allow communication to certain ports. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.