MirrorFace is a Chinese-speaking threat group targeting high-value entities in Japan.
Analyst brief
MirrorFace (also tracked as Earth Kasha) is a Chinese-speaking threat group targeting high-value entities in Japan, including media, government, diplomatic, and political sectors. The actor primarily gains initial access via Spearphishing Attachment/Link techniques and leverages malware such as Cobalt Strike, MirrorStealer, and LODEINFO to steal credentials and exfiltrate sensitive data. Defenders should pay close attention to Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (T1048.002), monitor lateral movement attempts via RDP, and track the abuse of tools like BITSAdmin and Wevtutil.
MirrorFace
Earth Kasha
unknown
MirrorFace is a Chinese-speaking advanced persistent threat group that has been targeting high-value organizations in Japan, including media, government, diplomatic, and political entities. They have been conducting spear-phishing campaigns, utilizing malware such as LODEINFO and MirrorStealer to steal credentials and exfiltrate sensitive data. While there is speculation about their connection to APT10, ESET currently track them as a separate entity.