MirrorStealer
MITRE ATT&CK: S9022 View on attack.mitre.org
Aliases: MirrorStealer
- First seen
- 2022-01-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:09:03
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:jp
Context
MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.
Detection coverage
- 24 Sigma rules
Malware & tools used
- Credentials from Password Stores (attack-pattern)
- Group Policy Preferences (attack-pattern)
- Local Data Staging (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
Used by threat actors
- MirrorFace (threat-actor)
Reports & references
- ESET — Unmasking Mirrorface Operation Liberalface Targeting Japanese Political Entities (report)
- MITRE ATT&CK — S9022 (report)