Threat actor · G1054
MirrorFace
Also known as Earth Kasha.
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
ATT&CK techniques
43 mappedT1003.001T1003.002T1003.003T1005T1007T1016T1018T1021.001T1021.002T1027.013T1033T1036.008T1047T1048.002T1057T1059.003T1059.005T1070.004T1071.002T1074.002T1082T1083T1087.002T1090T1114.001T1190T1204.002T1221T1482T1553.002T1556.002T1560.001T1566.001T1566.002T1574.001T1587.001T1588.002T1591T1614.001T1684.001T1685T1685.005T1686.003