MirrorStealer

MITRE ATT&CK: S9022 View on attack.mitre.org

Aliases: MirrorStealer

First seen
2022-01-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:09:03

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:jp

Context

MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.

Detection coverage

  • 24 Sigma rules

Malware & tools used

  • Credentials from Password Stores (attack-pattern)
  • Group Policy Preferences (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)

Used by threat actors

Reports & references

  • ESET — Unmasking Mirrorface Operation Liberalface Targeting Japanese Political Entities (report)
  • MITRE ATT&CK — S9022 (report)

External references