MirrorBlast
- First seen
- 2021-10-01 00:00:00
- Malware type
- trojan, downloader
- Family
- Malware family
- Profile updated
- 2026-07-07 15:01:39
Targeted industries: financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:ca
Context
According to Minerva Labs, MirrorBlast malware is a trojan that is known for attacking users’ browsers. It usually pretends to be a legitimate browser add-on however it has now evolved additional capabilities, whereby other malwares are installed simultaneously. Recently, this trojan is thought to have tentative links to TA505 and PYSA groups.
Reports & references
- proofpoint.com — Whatta Ta Ta505 Ramps Activity Delivers New Flawedgrace Variant (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Mirrorblast (report)
- threatresearch.ext.hp.com — Mirrorblast And Ta505 Examining Similarities In Tactics Techniques And Procedures (report)
- blog.morphisec.com — Explosive New Mirrorblast Campaign Targets Financial Companies (report)
- frsecure.com — The Rebol Yell New Rebol Exploit (report)
- proofpoint.com — Daily Ruleset Update Summary 20210924 (report)