MirrorFace
MITRE ATT&CK: G1054 View on attack.mitre.org
Aliases: Earth Kasha, MirrorFace
- First seen
- 2019-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:08:07
Targeted industries: media-and-entertainment defense-and-aerospace government-and-public-sector financial-services manufacturing education-and-nonprofits
Targeted regions: country_code:jp country_code:cn country_code:cz
Context
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
Detection coverage
- 147 YARA rules
- 853 Sigma rules
Malware & tools used
- Spearphishing Link (attack-pattern)
- Process Discovery (attack-pattern)
- Windows Host Firewall (attack-pattern)
- Remote Data Staging (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Domain Account (attack-pattern)
- System Language Discovery (attack-pattern)
- Gather Victim Org Information (attack-pattern)
- Proxy (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Malware (attack-pattern)
- File Deletion (attack-pattern)
- Security Account Manager (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Impersonation (attack-pattern)
- Tool (attack-pattern)
- LSASS Memory (attack-pattern)
- Malicious File (attack-pattern)
- Remote System Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Code Signing (attack-pattern)
- Data from Local System (attack-pattern)
- Windows Command Shell (attack-pattern)
Reports & references
- blog.sekoia.io — My Teas Not Cold An Overview Of China Cyber Threat (report)
- ESET — Unmasking Mirrorface Operation Liberalface Targeting Japanese Political Entities (report)
- web-assets.esetstatic.com — Eset Apt Activity Report T32022 (report)
- Trend Micro — Return Of Anel In The Recent Earth Kasha Spearphishing Campaign (report)
- Trend Micro — Lodeinfo Campaign Of Earth Kasha (report)
- MITRE ATT&CK — G1054 (report)
- blogs.jpcert.or.jp — Mirrorface Attack Against Japanese Organisations (report)
- Kaspersky — 107742 (report)
- Kaspersky — 107745 (report)
- Trend Micro — Earth Kasha Updates Ttps (report)
Attributed from
- Operation AkaiRyū (campaign)
External references
- mitre-attack — G1054
- Earth Kasha
- ESET MirrorFace DEC 2022
- Trend Micro Earth Kasha Updates APR 2025
- Kaspersky LODEINFO OCT 2022
- Kaspersky LODEINFO Part II OCT 2022
- JPCERT MirrorFace JUL 2024
- Trend Micro Earth Kasha NOV 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy