Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware MirrorStealer

MirrorStealer

TLP:CLEAR
Family

AI Analysis

· 13 hours ago

Enhanced Description

MirrorStealer is a sophisticated credential‑stealing component that has been weaponized as part of the MirrorFace campaign since at least 2022. Designed primarily for Windows platforms, it targets a broad spectrum of applications—including web browsers (Chrome, Edge, Firefox), email clients such as Microsoft Outlook, and other credential‑storing utilities—to harvest cached usernames and passwords from local credentials vaults. Unlike many traditional keyloggers or disk‑resident trojans, MirrorStealer is delivered directly into system memory via commands issued by the LODEINFO module. By deploying itself in RAM, it avoids creating persistent files on the filesystem, thereby evading conventional signature‑based detection and complicating forensic analysis. Once active, the malware enumerates credential databases (e.g., Chrome\

Description

MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.(Citation: ESET MirrorFace DEC 2022)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.