MirrorFace

MITRE ATT&CK: G1054 View on attack.mitre.org

Aliases: Earth Kasha, MirrorFace

First seen
2019-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:08:07

Targeted industries: media-and-entertainment defense-and-aerospace government-and-public-sector financial-services manufacturing education-and-nonprofits

Targeted regions: country_code:jp country_code:cn country_code:cz

Context

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.

Detection coverage

  • 147 YARA rules
  • 853 Sigma rules

Malware & tools used

  • Spearphishing Link (attack-pattern)
  • Process Discovery (attack-pattern)
  • Windows Host Firewall (attack-pattern)
  • Remote Data Staging (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Domain Account (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Gather Victim Org Information (attack-pattern)
  • Proxy (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Malware (attack-pattern)
  • File Deletion (attack-pattern)
  • Security Account Manager (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Impersonation (attack-pattern)
  • Tool (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Malicious File (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • Data from Local System (attack-pattern)
  • Windows Command Shell (attack-pattern)

Reports & references

  • blog.sekoia.io — My Teas Not Cold An Overview Of China Cyber Threat (report)
  • ESET — Unmasking Mirrorface Operation Liberalface Targeting Japanese Political Entities (report)
  • web-assets.esetstatic.com — Eset Apt Activity Report T32022 (report)
  • Trend Micro — Return Of Anel In The Recent Earth Kasha Spearphishing Campaign (report)
  • Trend Micro — Lodeinfo Campaign Of Earth Kasha (report)
  • MITRE ATT&CK — G1054 (report)
  • blogs.jpcert.or.jp — Mirrorface Attack Against Japanese Organisations (report)
  • Kaspersky — 107742 (report)
  • Kaspersky — 107745 (report)
  • Trend Micro — Earth Kasha Updates Ttps (report)

Attributed from

  • Operation AkaiRyū (campaign)

External references