ATT&CKSoftwareMirrorStealer

MirrorStealer

S9022

Malware.View on attack.mitre.org

About this malware

MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1074.001
Local Data Staging

MirrorStealer has stored stolen credentials on the local machine in `%TEMP%\31558.txt`.

T1552.006
Group Policy Preferences

MirrorStealer can target Group Policy Preferences for credentials.

T1555
Credentials from Password Stores

MirrorStealer has the ability to steal credentials from email clients.

T1555.003
Credentials from Web Browsers

MirrorStealer can steal credentials stored in browsers.

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET MirrorFace DEC 2022 Open source
    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.