LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S9023: HiddenFace

HiddenFace is a modular backdoor developed and used exclusively by MirrorFace since at least 2021. HiddenFace can communicate both actively and passively and has been used against political and academic targets.[1][2][3]

EnterpriseS9023MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

HiddenFace matters because it is described by ATT&CK as a Windows modular backdoor used exclusively by MirrorFace since at least 2021, with reported use against political and academic targets. For leaders, the key issue is not one malware name; it is whether the organization can recognize and investigate a stealthy backdoor that may use persistence, discovery, obfuscation, process injection, registry changes, and resilient command-and-control behaviors.

Executive priority

Prioritize HiddenFace as a validation case for Windows endpoint visibility, egress monitoring, and incident response readiness. The ATT&CK relationships show behaviors that can affect business continuity and evidence quality: scheduled-task persistence, registry modification, local data collection, tool transfer, fallback channels, tunneling, non-standard ports, and DGA-style C2. Executives should ask whether SOC and IR teams can prove coverage for these behavior classes, especially in politically sensitive, academic, public-sector, or Japan/Central Europe-facing risk contexts referenced by the related campaign and group descriptions.

Technical view

ATT&CK provides no official detection text for HiddenFace, so defenders should build coverage from the related techniques. On Windows, validate telemetry and analytics for scheduled task creation or modification, registry modifications, process injection indicators, user/system/process/security-software discovery, timestomping, mutex or execution-guardrail behavior, decoding/deobfuscation activity, file ingress, and unusual command-and-control patterns. Network validation should include fallback channels, internal proxying, non-application-layer or tunneled communications, DGA-like domain activity, and protocol/port mismatches. Treat detections as behavior-based rather than name-based because the object is described as modular and includes multiple stealth and C2-related relationships.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows scheduled task creation, modification, and execution events
  • Windows Registry modification telemetry
  • Endpoint detection events related to process injection or suspicious cross-process activity
  • File creation, modification time, and timestamp anomaly evidence

Detection direction

  • Because ATT&CK lists no official detection guidance, start with coverage mapping against the related techniques rather than assuming malware-signature detection is sufficient.
  • Tune Windows persistence analytics around scheduled tasks and registry changes, separating legitimate administration and software deployment from unusual task names, paths, users, or execution timing.
  • Correlate discovery activity, such as user, system, process, and security software discovery, with later persistence, C2, file transfer, or collection behavior to reduce false positives.
  • Validate network analytics for protocol/port mismatches, tunneling, DGA-like DNS behavior, internal proxy patterns, and fallback communications rather than relying only on known indicators.
  • Account for stealth behaviors including dynamic API resolution, encrypted or encoded files, deobfuscation, process injection, timestomping, execution guardrails, mutex checks, and time-based checks, which can reduce static-analysis and sandbox confidence.

Mitigation priorities

  • Confirm baseline Windows hardening and least-privilege controls for persistence-sensitive areas such as scheduled tasks and Registry keys.
  • Ensure endpoint protection and EDR policies collect the telemetry needed for process injection, discovery, persistence, file modification, and suspicious execution analysis.
  • Restrict and monitor unnecessary outbound traffic, non-standard ports, tunneled protocols, and unusual DNS behavior through egress controls and network logging.
  • Strengthen IR playbooks for backdoor investigations, including preservation of endpoint timelines, task scheduler data, Registry hives, DNS history, proxy/firewall logs, and downloaded files.
  • Use detection engineering exercises or purple-team validation to test the related ATT&CK behaviors without assuming the organization can detect HiddenFace by name.
Additional notes and limits

HiddenFace is a malware/software object in ATT&CK Enterprise with Windows as the supplied platform. The strongest defensive value comes from its relationship set: collection from local systems, persistence through scheduled tasks and registry modification, discovery behaviors, stealth techniques, and multiple command-and-control resilience patterns. The related group and campaign context can help prioritize monitoring for organizations with relevant geopolitical, academic, public-sector, or regional exposure, but local telemetry is required before making any exposure or attribution judgment.

ATT&CK does not provide official detection text, aliases, labels, or tactics for this malware object. The supplied data does not include indicators of compromise, hashes, filenames, infrastructure, vulnerabilities, or confirmed customer exposure. Some related technique platform lists are broader or not Windows-specific, so this take treats Windows as the supported malware platform and uses related techniques as behavior context rather than proof of every implementation detail.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

HiddenFace

HiddenFace is a modular backdoor developed and used exclusively by MirrorFace since at least 2021. HiddenFace can communicate both actively and passively and has been used against political and academic targets.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1053.005Scheduled TaskSub-technique

HiddenFace has used scheduled tasks for execution and persistence.[4][2]

EnterpriseT1571Non-Standard Port

HiddenFace's passive mode listens on TCP 47000.[2][1]

EnterpriseT1573.002Asymmetric CryptographySub-technique

HiddenFace can use RSA-2048 in addition to symmetric algorithms in C2.[2]

EnterpriseT1090.001Internal ProxySub-technique

HiddenFace can act as an internal HTTP proxy within the targeted environment.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

HiddenFace has encrypted its payload with AES.[4][1]

EnterpriseT1480.002Mutual ExclusionSub-technique

HiddenFace can create a mutex to ensure only one instance is running at a time.[4]

EnterpriseT1095Non-Application Layer Protocol

HiddenFace can use a custom TCP protocol over Port 443 for C2.[4][2][1]

EnterpriseT1497.003Time Based ChecksSub-technique

HiddenFace can sleep randomly between 30 and 60 seconds to avoid behavioral analysis.[4]

EnterpriseT1008Fallback Channels

HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands.[2]

EnterpriseT1033System Owner/User Discovery

HiddenFace can collect the username associated with the compromised host.[4]

EnterpriseT1005Data from Local System

HiddenFace can upload files from the victim machine to C2 nodes.[2][1]

EnterpriseT1105Ingress Tool Transfer

HiddenFace can download files from the C2 to victim systems.[2][1]

EnterpriseT1027.007Dynamic API ResolutionSub-technique

HiddenFace can dynamically resolve Windows APIs.[4][2]

EnterpriseT1518.001Security Software DiscoverySub-technique

HiddenFace can identify processes identified with security applications and tooling.[4][2]

EnterpriseT1070.006TimestompSub-technique

HiddenFace can alter timestamps for directory content on targeted machines.[4][2][1]

EnterpriseT1568.002Domain Generation AlgorithmsSub-technique

HiddenFace has used dynamic domain generation algorithms in C2.[4][2][3][1]

EnterpriseT1082System Information Discovery

HiddenFace can enumerate the hostname and username of the compromised system.[4][2][1]

EnterpriseT1057Process Discovery

HiddenFace can check running processes against a list of blocklisted applications.[4]

EnterpriseT1055Process Injection

HiddenFace can inject code directly into legitimate applications.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

HiddenFace can use a randomly selected symmetric encryption algorithm for C2.[4]

EnterpriseT1572Protocol Tunneling

HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2.[3]

EnterpriseT1140Deobfuscate/Decode Files or Information

HiddenFace has the ability to decrypt its payload prior to execution.[4][1]

EnterpriseT1112Modify Registry

HiddenFace can store its configuration file in the Registry.[1]

EnterpriseT1480Execution Guardrails

HiddenFace can check for the presence of specific analysis tools and will terminate itself if they are found.[2]

EnterpriseT1686.003Windows Host FirewallSub-technique

HiddenFace can reconfigure Windows firewalls to enable communication by adding a rule named “Cortana” to allow inbound connection to TCP/47000.[4][2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1054: MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.[1][2][3][4][5][6]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
f3cbc91aa05efaa6...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlef3cbc91aa05e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  2. [2]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  3. [3]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  4. [4]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  5. [5]
    Trend Micro Earth Kasha Anel NOV 2024

    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

    Open source URL
  6. [6]
    ESET MirrorFace 2025

    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

    Open source URL
  7. [7]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  8. [8]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  9. [9]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  10. [10]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  11. [11]
    NOOPDOOR

    (Citation: ESET HiddenFace 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)

  12. [12]
    NOOPDOOR

    (Citation: ESET HiddenFace 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)

  13. [13]
    NOOPDOOR

    (Citation: ESET HiddenFace 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)

  14. [14]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  15. [15]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  16. [16]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  17. [17]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  18. [18]
    mitre-attackS9023
    Open source URL
  19. [19]
    mitre-attackS9023
    Open source URL
  20. [20]
    mitre-attackS9023
    Open source URL
  21. [21]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  22. [22]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  23. [23]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  24. [24]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  25. [25]
    ESET MirrorFace 2025

    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

    Open source URL
  26. [26]
    Trend Micro Earth Kasha Anel NOV 2024

    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

    Open source URL
  27. [27]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  28. [28]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  29. [29]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  30. [30]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  31. [31]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  32. [32]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  33. [33]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  34. [34]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  35. [35]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  36. [36]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  37. [37]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  38. [38]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  39. [39]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  40. [40]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  41. [41]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  42. [42]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  43. [43]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  44. [44]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  45. [45]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  46. [46]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  47. [47]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  48. [48]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  49. [49]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  50. [50]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  51. [51]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  52. [52]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  53. [53]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  54. [54]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  55. [55]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  56. [56]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  57. [57]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  58. [58]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  59. [59]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  60. [60]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  61. [61]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  62. [62]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  63. [63]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  64. [64]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  65. [65]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  66. [66]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  67. [67]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  68. [68]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  69. [69]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  70. [70]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  71. [71]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  72. [72]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  73. [73]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  74. [74]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  75. [75]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  76. [76]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  77. [77]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  78. [78]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  79. [79]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  80. [80]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  81. [81]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  82. [82]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  83. [83]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  84. [84]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  85. [85]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  86. [86]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  87. [87]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  88. [88]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  89. [89]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  90. [90]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  91. [91]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  92. [92]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  93. [93]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  94. [94]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  95. [95]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  96. [96]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  97. [97]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  98. [98]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  99. [99]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  100. [100]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  101. [101]
    Trend Micro Earth Kasha Updates APR 2025

    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

    Open source URL
  102. [102]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  103. [103]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  104. [104]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  105. [105]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
  106. [106]
    ESET HiddenFace 2024

    Breitenbacher, D. (2024). Unmasking HiddenFace. Retrieved April 17, 2026.

    Open source URL
  107. [107]
    Trend Micro Earth Kasha NOV 2024

    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.