LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1054: MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

EnterpriseG1054GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1054: MirrorFace describes [MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent [MirrorFa...

Executive priority

G1054: MirrorFace is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1054: MirrorFace by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1054: MirrorFace appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

43 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.002Spearphishing LinkSub-technique

MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation.[6]

EnterpriseT1057Process Discovery

MirrorFace has used Tasklist on compromised hosts for discovery.[4]

EnterpriseT1686.003Windows Host FirewallSub-technique

MirrorFace can modify the system firewall to allow communication to certain ports.[4]

EnterpriseT1074.002Remote Data StagingSub-technique

MirrorFace has gathered data and files of interest on a single victim machine.[5]

EnterpriseT1685Disable or Modify Tools

MirrorFace has disabled Windows Defender in compromised environments.[4]

EnterpriseT1087.002Domain AccountSub-technique

MirrorFace has used native Windows tools to obtain domain user information.[5]

EnterpriseT1614.001System Language DiscoverySub-technique

MirrorFace has deployed shellcode to check for Japanese Microsoft Office settings.CitationITOCHU LODEINFO JAN 2024

EnterpriseT1591Gather Victim Org Information

MirrorFace has placed specific content in phishing emails to target members of particular political parties.[3]

EnterpriseT1090Proxy

MirrorFace has used the GO Simple Tunnel (GOST) proxy tool.[4]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

MirrorFace has deleted Windows event logs.[4]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

MirrorFace has used RDP to exfiltrate files of interest.[5]

EnterpriseT1587.001MalwareSub-technique

MirrorFace has created and continued to develop custom strains of malware including LODEINFO.[3]

EnterpriseT1070.004File DeletionSub-technique

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.[3][5][6][4]

EnterpriseT1003.002Security Account ManagerSub-technique

MirrorFace has used vssadmin to copy registry hives including SAM.[5][4]

EnterpriseT1083File and Directory Discovery

MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.[3][5][4]

EnterpriseT1482Domain Trust Discovery

MirrorFace has run `nltest.exe /domain_trusts` on compromised systems to discover domain relationships.[5]

EnterpriseT1684.001ImpersonationSub-technique

MirrorFace has sent targeted emails purporting to be from a Japanese political party’s PR department.[3]

EnterpriseT1588.002ToolSub-technique

MirrorFace has used tools including the Secure Copy Protocol (SCP) client from PuTTY and Cobalt Strike.[3][5][4]

EnterpriseT1003.001LSASS MemorySub-technique

MirrorFace has dumped LSASS memory for credential access.[4]

EnterpriseT1204.002Malicious FileSub-technique

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.[1][3]CitationITOCHU LODEINFO JAN 2024[6]

EnterpriseT1018Remote System Discovery

MirrorFace has used Ping for system discovery.[4]

EnterpriseT1016System Network Configuration Discovery

MirrorFace has used ipconfig for reconnaissance.[4]

EnterpriseT1553.002Code SigningSub-technique

MirrorFace has abused a known Microsoft digital signature verification issues to append encrypted data to digital signatures that still appear to be validly signed.[3]

EnterpriseT1005Data from Local System

MirrorFace gathered data and files of interest from victim's systems.[5]

EnterpriseT1059.003Windows Command ShellSub-technique

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.[5][6][4][4]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

MirrorFace has sent spearphishing emails with malicious attachments to deliver malware payloads.[1][3]CitationITOCHU LODEINFO JAN 2024

EnterpriseT1059.005Visual BasicSub-technique

MirrorFace has used remote templates with VBA code in malware infection chains.CitationITOCHU LODEINFO JAN 2024

EnterpriseT1007System Service Discovery

MirrorFace has used Tasklist for discovery post compromise.[4]

EnterpriseT1082System Information Discovery

MirrorFace has employed malicious macros and native Windows tools such as csvde.exe, nltest.exe and quser.exe for discovery.CitationITOCHU LODEINFO JAN 2024[5][4]

EnterpriseT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolSub-technique

MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration.[4]

EnterpriseT1574.001DLLSub-technique

MirrorFace has used legitimate EXE files to load malicious DLLs via sideloading.[1][3]CitationITOCHU LODEINFO JAN 2024[5]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

MirrorFace has used SMB to copy malware between systems in compromised environments.[5][4]

EnterpriseT1071.002File Transfer ProtocolsSub-technique

MirrorFace has used the the PuTTY suite Secure Copy Protocol (SCP) client for file transfer.[3]

EnterpriseT1190Exploit Public-Facing Application

MirrorFace has exploited vulnerabilities in Fortigate and Array AG devices for initial access.[4]

EnterpriseT1036.008Masquerade File TypeSub-technique

MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files.CitationITOCHU LODEINFO JAN 2024

EnterpriseT1003.003NTDSSub-technique

MirrorFace has dumped NTDS.dit through volume shadow copies.[5][4]

EnterpriseT1560.001Archive via UtilitySub-technique

MirrorFace has used rar.exe and the Makecab utility to archive files of interest prior to exfiltration.[3][5][4]

EnterpriseT1221Template Injection

MirrorFace has used remote template injection to retrieve malicious payloads from the C2.CitationITOCHU LODEINFO JAN 2024

EnterpriseT1556.002Password Filter DLLSub-technique

MirrorFace has used a tool named MRSAStealer as a password filter to collect credentials on password changes.[3]

EnterpriseT1047Windows Management Instrumentation

MirrorFace has leveraged WMIC on targeted systems post compromise.[4]

EnterpriseT1114.001Local Email CollectionSub-technique

MirrorFace has exfiltrated stored emails from compromised hosts.[3]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

MirrorFace has used Base64 encoded shellcode in infection chains to evade detection.CitationITOCHU LODEINFO JAN 2024

EnterpriseT1033System Owner/User Discovery

MirrorFace has used Windows native tools to enumerate user information.[5]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
ToolEnterprise

S0359: Nltest

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.[1]

Windows
ToolEnterprise

S0057: Tasklist

The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It is packaged with Windows operating systems and can be executed from the command-line interface. [1]

ToolEnterprise

S0100: ipconfig

ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration. [1]

MalwareEnterprise

S9020: LODEINFO

LODEINFO is a fileless backdoor malware first identified in 2020 that has been used by actors including MirrorFace, primarily against media, diplomatic, governmental, and public sector organizations in Japan.[1][2][3]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
a6e9006588157cf0...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundlea6e900658815…
19.11.0Older bundle00c579b3156f…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Kaspersky LODEINFO OCT 2022

    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.

    Open source URL
  2. [2]
    Kaspersky LODEINFO Part II OCT 2022

    Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.

    Open source URL
  3. [3]
    ESET MirrorFace DEC 2022

    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.

    Open source URL
  4. [4]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  5. [5]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  6. [6]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  7. [7]
    Earth Kasha

    (Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)

  8. [8]
    mitre-attackG1054
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.