Threat group.View on attack.mitre.org
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
MirrorFace has dumped LSASS memory for credential access. |
| T1003.002 Security Account Manager |
MirrorFace has used vssadmin to copy registry hives including SAM. |
| T1003.003 NTDS |
MirrorFace has dumped NTDS.dit through volume shadow copies. |
| T1005 Data from Local System |
MirrorFace gathered data and files of interest from victim's systems. |
| T1007 System Service Discovery |
MirrorFace has used Tasklist for discovery post compromise. |
| T1016 System Network Configuration Discovery |
MirrorFace has used ipconfig for reconnaissance. |
| T1018 Remote System Discovery |
MirrorFace has used Ping for system discovery. |
| T1021.001 Remote Desktop Protocol |
MirrorFace has used RDP to exfiltrate files of interest. |
| T1021.002 SMB/Windows Admin Shares |
MirrorFace has used SMB to copy malware between systems in compromised environments. |
| T1027.013 Encrypted/Encoded File |
MirrorFace has used Base64 encoded shellcode in infection chains to evade detection. |
| T1033 System Owner/User Discovery |
MirrorFace has used Windows native tools to enumerate user information. |
| T1036.008 Masquerade File Type |
MirrorFace has crafted malware payloads to appear as Privacy-Enhanced Mail (PEM) files. |
| T1047 Windows Management Instrumentation |
MirrorFace has leveraged WMIC on targeted systems post compromise. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MirrorFace has used Secure File Transfer Protocol (SFTP) for file exfiltration. |
| T1057 Process Discovery |
MirrorFace has used Tasklist on compromised hosts for discovery. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.