Overview 22 indicators
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
| ipv4 | 17 | G1054.json |
| url | 3 | G1054.json |
| domain | 2 | G1054-domain.txt |
Techniques 43 ATT&CK
Open in ATT&CK Navigator → or download the layer (43 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1005 Data from Local System
- T1007 System Service Discovery
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1027.013 Encrypted/Encoded File
- T1033 System Owner/User Discovery
- T1036.008 Masquerade File Type
- T1047 Windows Management Instrumentation
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1070.004 File Deletion
- T1071.002 File Transfer Protocols
- T1074.002 Remote Data Staging
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1090 Proxy
- T1114.001 Local Email Collection
- T1190 Exploit Public-Facing Application
- T1204.002 Malicious File
- T1221 Template Injection
- T1482 Domain Trust Discovery
- T1553.002 Code Signing
- T1556.002 Password Filter DLL
- T1560.001 Archive via Utility
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1574.001 DLL
- T1587.001 Malware
- T1588.002 Tool
- T1591 Gather Victim Org Information
- T1614.001 System Language Discovery
- T1684.001 Impersonation
- T1685 Disable or Modify Tools
- T1685.005 Clear Windows Event Logs
- T1686.003 Windows Host Firewall
Software 16
- Net
- Tasklist
- Ping
- ipconfig
- nbtstat
- Cobalt Strike
- BITSAdmin
- UPPERCUT
- Nltest
- Wevtutil
- LODEINFO
- DOWNIISSA
- MirrorStealer
- HiddenFace
- NOOPLDR
- ROAMINGHOUSE
Principal sources 11 reports
Ranked by how many of this actor's indicators each report brought in.
- 17x.com/780thC/status/1856027964112044127
- 17x.com/pancak3lullz/status/1862959850180804935
- 17x.com/pancak3lullz/status/1863005095375319345
- 17therecord.media/china-linked-hackers-tasked-with-japane…
- 17search.censys.io/search?q=services.tls.certificates.leaf…
- 5welivesecurity.com/2022/12/14/unmasking-mirrorface-operati…
- 5otx.alienvault.com/pulse/639b01a88df8698311dc2b43
- 5virustotal.com/gui/ip-address/167.179.116.56/relations
Related groups 5
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 22 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/780thC/status/1856027964112044127 · x.com/pancak3lullz/status/1862959850180804935 · x.com/pancak3lullz/status/1863005095375319345 · therecord.media/china-linked-hackers-tasked-with-japane… · search.censys.io/search?q=services.tls.certificates.leaf…
104.238.149.37:3389 108.160.138.20:3389 139.180.197.13:3389 149.28.31.17:3389 167.179.105.29:3389 198.13.51.211:3389 198.13.55.8:3389 207.148.104.176:3389 43.224.34.61:3389 45.32.14.107:3389 45.32.18.42:3389 45.76.193.104:3389 45.76.202.254:3389 45.76.202.98:3389 45.76.97.113:3389 45.77.28.195:3389 45.77.29.108:3389 -
welivesecurity.com/2022/12/14/unmasking-mirrorface-operati… · otx.alienvault.com/pulse/639b01a88df8698311dc2b43 · virustotal.com/gui/ip-address/167.179.116.56/relations · virustotal.com/gui/ip-address/172.105.217.233/relations · virustotal.com/gui/file/f53c5fd78000755ccfff11d2f1b7d6… · virustotal.com/gui/file/a8ec766eee6cc3c6416519f8407ac5…
domain aesorunwe.com domain ninesmn.com url http://167.179.116.56 url http://172.105.217.233 url http://45.32.13.180
Further reading 17
- attack.mitre.org/groups/G1054
- blogs.jpcert.or.jp/en/2024/07/mirrorface-attack-against-ja…
- securelist.com/apt10-tracking-down-lodeinfo-2022-part-…
- securelist.com/apt10-tracking-down-lodeinfo-2022-part-…
- trendmicro.com/en_us/research/24/k/lodeinfo-campaign-o…
- trendmicro.com/en_us/research/25/d/earth-kasha-updates…
- welivesecurity.com/2022/12/14/unmasking-mirrorface-operati…
- therecord.media/china-linked-hackers-tasked-with-japane…
- virustotal.com/gui/ip-address/172.105.217.233/relations
- virustotal.com/gui/file/f53c5fd78000755ccfff11d2f1b7d6…
- x.com/pancak3lullz/status/1862959850180804935
- x.com/780thC/status/1856027964112044127
- otx.alienvault.com/pulse/639b01a88df8698311dc2b43
- virustotal.com/gui/file/a8ec766eee6cc3c6416519f8407ac5…
- search.censys.io/search?q=services.tls.certificates.leaf…
- virustotal.com/gui/ip-address/167.179.116.56/relations
- x.com/pancak3lullz/status/1863005095375319345