G1054: MirrorFace
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]
Security context for executives and security teams
G1054: MirrorFace describes [MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent [MirrorFa...
Executive priority
G1054: MirrorFace is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1054: MirrorFace by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1054: MirrorFace appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
MirrorFace
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation.[6] |
| Enterprise | T1057 | Process Discovery | MirrorFace has used Tasklist on compromised hosts for discovery.[4] |
| Enterprise | T1686.003 | Windows Host FirewallSub-technique | MirrorFace can modify the system firewall to allow communication to certain ports.[4] |
| Enterprise | T1074.002 | Remote Data StagingSub-technique | MirrorFace has gathered data and files of interest on a single victim machine.[5] |
| Enterprise | T1685 | Disable or Modify Tools | MirrorFace has disabled Windows Defender in compromised environments.[4] |
| Enterprise | T1087.002 | Domain AccountSub-technique | MirrorFace has used native Windows tools to obtain domain user information.[5] |
| Enterprise | T1614.001 | System Language DiscoverySub-technique | MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.CitationITOCHU LODEINFO JAN 2024 |
| Enterprise | T1591 | Gather Victim Org Information | MirrorFace has placed specific content in phishing emails to target members of particular political parties.[3] |
| Enterprise | T1090 | Proxy | MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.[4] |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | MirrorFace has deleted Windows event logs.[4] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | MirrorFace has used RDP to exfiltrate files of interest.[5] |
| Enterprise | T1587.001 | MalwareSub-technique | MirrorFace has created and continued to develop custom strains of malware including LODEINFO.[3] |
| Enterprise | T1070.004 | File DeletionSub-technique | MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.[3][5][6][4] |
| Enterprise | T1003.002 | Security Account ManagerSub-technique | MirrorFace has used vssadmin to copy registry hives including SAM.[5][4] |
| Enterprise | T1083 | File and Directory Discovery | MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.[3][5][4] |
| Enterprise | T1482 | Domain Trust Discovery | MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.[5] |
| Enterprise | T1684.001 | ImpersonationSub-technique | MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department.[3] |
| Enterprise | T1588.002 | ToolSub-technique | MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.[3][5][4] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | MirrorFace has dumped LSASS memory for credential access.[4] |
| Enterprise | T1204.002 | Malicious FileSub-technique | MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.[1][3]CitationITOCHU LODEINFO JAN 2024[6] |
| Enterprise | T1018 | Remote System Discovery | MirrorFace has used Ping for system discovery.[4] |
| Enterprise | T1016 | System Network Configuration Discovery | MirrorFace has used ipconfig for reconnaissance.[4] |
| Enterprise | T1553.002 | Code SigningSub-technique | MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.[3] |
| Enterprise | T1005 | Data from Local System | MirrorFace gathered data and files of interest from victim's systems.[5] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.[5][6][4][4] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.[1][3]CitationITOCHU LODEINFO JAN 2024 |
| Enterprise | T1059.005 | Visual BasicSub-technique | MirrorFace has used remote templates with VBA code in malware infection chains.CitationITOCHU LODEINFO JAN 2024 |
| Enterprise | T1007 | System Service Discovery | MirrorFace has used Tasklist for discovery post compromise.[4] |
| Enterprise | T1082 | System Information Discovery | MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.CitationITOCHU LODEINFO JAN 2024[5][4] |
| Enterprise | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolSub-technique | MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.[4] |
| Enterprise | T1574.001 | DLLSub-technique | MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.[1][3]CitationITOCHU LODEINFO JAN 2024[5] |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | MirrorFace has used SMB to copy malware between systems in compromised environments.[5][4] |
| Enterprise | T1071.002 | File Transfer ProtocolsSub-technique | MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.[3] |
| Enterprise | T1190 | Exploit Public-Facing Application | MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access.[4] |
| Enterprise | T1036.008 | Masquerade File TypeSub-technique | MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.CitationITOCHU LODEINFO JAN 2024 |
| Enterprise | T1003.003 | NTDSSub-technique | MirrorFace has dumped NTDS.dit through volume shadow copies.[5][4] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.[3][5][4] |
| Enterprise | T1221 | Template Injection | MirrorFace has used remote template injection to retrieve malicious payloads from the C2.CitationITOCHU LODEINFO JAN 2024 |
| Enterprise | T1556.002 | Password Filter DLLSub-technique | MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes.[3] |
| Enterprise | T1047 | Windows Management Instrumentation | MirrorFace has leveraged WMIC on targeted systems post compromise.[4] |
| Enterprise | T1114.001 | Local Email CollectionSub-technique | MirrorFace has exfiltrated stored emails from compromised hosts.[3] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.CitationITOCHU LODEINFO JAN 2024 |
| Enterprise | T1033 | System Owner/User Discovery | MirrorFace has used Windows native tools to enumerate user information.[5] |
Groups, software, and campaigns
S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
S9022: MirrorStealer
MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.[1]
S0275: UPPERCUT
UPPERCUT is a 32-bit HTTP-based backdoor that has been used by menuPass since at least 2017.[1] Once thought to be exclusive to menuPass, UPPERCUT was also observed being used by menuPass-associated MirrorFace during Operation AkaiRyū.[2]
S0359: Nltest
S0190: BITSAdmin
S0057: Tasklist
S0100: ipconfig
S9020: LODEINFO
LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.[1][2][3]
S9026: ROAMINGHOUSE
ROAMINGHOUSE is a dropper malware used by MirrorFace to extract and execute embedded payloads including UPPERCUT components.[1]
S9021: DOWNIISSA
DOWNIISSA is a shellcode downloader that has been used by MirrorFace since at least 2022 to deploy payloads, including the LODEINFO backdoor.[1]
S0102: nbtstat
C0060: Operation AkaiRyū
Operation AkaiRyū (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central Europe. Operation AkaiRyū notably included the first reported targeting of a European entity by MirrorFace, as well as their use of UPPERCUT, which was thought to be exclusive to menuPass.[1][2]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | a6e900658815… | ||
| 19.1 | 1.0 | Older bundle | 00c579b3156f… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Kaspersky LODEINFO OCT 2022
Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.
Open source URL - [2]Kaspersky LODEINFO Part II OCT 2022
Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.
Open source URL - [3]ESET MirrorFace DEC 2022
Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.
Open source URL - [4]JPCERT MirrorFace JUL 2024
Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
Open source URL - [5]Trend Micro Earth Kasha NOV 2024
Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.
Open source URL - [6]Trend Micro Earth Kasha Updates APR 2025
Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.
Open source URL - [7]Earth Kasha
(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)
- [8]mitre-attackG1054Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
