Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Earth Kasha
43
techniques
16
software
11,251
corpus matches
profile
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
techniques
43 attributed · most-instrumented first
software
16 malware & tools attributed
Net
S0039
Tasklist
S0057
Ping
S0097
ipconfig
S0100
nbtstat
S0102
Cobalt Strike
S0154
BITSAdmin
S0190
UPPERCUT
S0275
Nltest
S0359
Wevtutil
S0645
read this carefully
11,251 corpus matches is not attribution
That count is indicators which exhibit techniques MirrorFace is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+31 more techniques
LODEINFO
S9020
DOWNIISSA
S9021
MirrorStealer
S9022
HiddenFace
S9023
NOOPLDR
S9025
ROAMINGHOUSE
S9026
showing 30 of 11,251
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.