ATT&CKSoftwareHiddenFace

HiddenFace

S9023

Malware.View on attack.mitre.org

About this malware

HiddenFace is a modular backdoor developed and used exclusively by MirrorFace since at least 2021. HiddenFace can communicate both actively and passively and has been used against political and academic targets.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

HiddenFace can upload files from the victim machine to C2 nodes.

T1008
Fallback Channels

HiddenFace can use active and passive C2 modes that use different encryption algorithms and backdoor commands.

T1027.007
Dynamic API Resolution

HiddenFace can dynamically resolve Windows APIs.

T1027.013
Encrypted/Encoded File

HiddenFace has encrypted its payload with AES.

T1033
System Owner/User Discovery

HiddenFace can collect the username associated with the compromised host.

T1053.005
Scheduled Task

HiddenFace has used scheduled tasks for execution and persistence.

T1055
Process Injection

HiddenFace can inject code directly into legitimate applications.

T1057
Process Discovery

HiddenFace can check running processes against a list of blocklisted applications.

T1070.006
Timestomp

HiddenFace can alter timestamps for directory content on targeted machines.

T1082
System Information Discovery

HiddenFace can enumerate the hostname and username of the compromised system.

T1090.001
Internal Proxy

HiddenFace can act as an internal HTTP proxy within the targeted environment.

T1095
Non-Application Layer Protocol

HiddenFace can use a custom TCP protocol over Port 443 for C2.

T1105
Ingress Tool Transfer

HiddenFace can download files from the C2 to victim systems.

T1112
Modify Registry

HiddenFace can store its configuration file in the Registry.

T1140
Deobfuscate/Decode Files or Information

HiddenFace has the ability to decrypt its payload prior to execution.

View all 25 procedure examples

Groups that use it1

Campaigns1

References3

  1. JPCERT MirrorFace JUL 2024 Open source
    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
  2. Trend Micro Earth Kasha NOV 2024 Open source
    Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.
  3. Trend Micro Earth Kasha Updates APR 2025 Open source
    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.