MirrorBlast

First seen
2021-10-01 00:00:00
Malware type
trojan, downloader
Family
Malware family
Profile updated
2026-07-07 15:01:39

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:ca

Context

According to Minerva Labs, MirrorBlast malware is a trojan that is known for attacking users’ browsers. It usually pretends to be a legitimate browser add-on however it has now evolved additional capabilities, whereby other malwares are installed simultaneously. Recently, this trojan is thought to have tentative links to TA505 and PYSA groups.

Reports & references

  • proofpoint.com — Whatta Ta Ta505 Ramps Activity Delivers New Flawedgrace Variant (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mirrorblast (report)
  • threatresearch.ext.hp.com — Mirrorblast And Ta505 Examining Similarities In Tactics Techniques And Procedures (report)
  • blog.morphisec.com — Explosive New Mirrorblast Campaign Targets Financial Companies (report)
  • frsecure.com — The Rebol Yell New Rebol Exploit (report)
  • proofpoint.com — Daily Ruleset Update Summary 20210924 (report)

External references