Threat Actor 🇨🇳 China
MirrorFace
Also known as: Earth Kasha
MirrorFace is a Chinese-speaking advanced persistent threat group that has been targeting high-value organizations in Japan, including media, government, diplomatic, and political entities. They have been conducting spear-phishing campaigns, utilizing malware such as LODEINFO and MirrorStealer to steal credentials and exfiltrate sensitive data. While there is speculation about their connection to APT10, ESET currently track them as a separate entity.
Indicators of Compromise 10
MITRE ATT&CK TTPs 10
T1021.001 T1059.001 T1071.001 T1078.002 T1098.002 T1110.001 T1136.001 T1543.001 T1556.004 T1566
Remote Desktop Protocol
Lateral Movement
PowerShell
Execution
Web Protocols
Command And Control
Domain Accounts
Defense Evasion
Additional Email Delegate Permissions
Persistence
Password Guessing
Credential Access
Local Account
Persistence
Launch Agent
Persistence
Network Device Authentication
Credential Access
Phishing
Initial Access