← All actors Recent activity

MirrorFace G1054

MIRRORFACE · lodeinfo · mirrorstealer

Indicators
22
Source reports
11
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20222024

Overview 22 indicators

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.

ipv417G1054.json
url3G1054.json
domain2G1054-domain.txt

Techniques 43 ATT&CK

Open in ATT&CK Navigator → or download the layer (43 techniques, layer 4.5)

Software 16

Principal sources 11 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 22 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 17 ipv42 yrs ago

    x.com/780thC/status/1856027964112044127 · x.com/pancak3lullz/status/1862959850180804935 · x.com/pancak3lullz/status/1863005095375319345 · therecord.media/china-linked-hackers-tasked-with-japane… · search.censys.io/search?q=services.tls.certificates.leaf…

    104.238.149.37:3389
    108.160.138.20:3389
    139.180.197.13:3389
    149.28.31.17:3389
    167.179.105.29:3389
    198.13.51.211:3389
    198.13.55.8:3389
    207.148.104.176:3389
    43.224.34.61:3389
    45.32.14.107:3389
    45.32.18.42:3389
    45.76.193.104:3389
    45.76.202.254:3389
    45.76.202.98:3389
    45.76.97.113:3389
    45.77.28.195:3389
    45.77.29.108:3389

  2. 2 domain, 3 url4 yrs ago

    welivesecurity.com/2022/12/14/unmasking-mirrorface-operati… · otx.alienvault.com/pulse/639b01a88df8698311dc2b43 · virustotal.com/gui/ip-address/167.179.116.56/relations · virustotal.com/gui/ip-address/172.105.217.233/relations · virustotal.com/gui/file/f53c5fd78000755ccfff11d2f1b7d6… · virustotal.com/gui/file/a8ec766eee6cc3c6416519f8407ac5…

    domainaesorunwe.com
    domainninesmn.com
    urlhttp://167.179.116.56
    urlhttp://172.105.217.233
    urlhttp://45.32.13.180

Further reading 17