Enhanced Description
MirrorStealer is a sophisticated credential‑stealing component that has been weaponized as part of the MirrorFace campaign since at least 2022. Designed primarily for Windows platforms, it targets a broad spectrum of applications—including web browsers (Chrome, Edge, Firefox), email clients such as Microsoft Outlook, and other credential‑storing utilities—to harvest cached usernames and passwords from local credentials vaults. Unlike many traditional keyloggers or disk‑resident trojans, MirrorStealer is delivered directly into system memory via commands issued by the LODEINFO module. By deploying itself in RAM, it avoids creating persistent files on the filesystem, thereby evading conventional signature‑based detection and complicating forensic analysis. Once active, the malware enumerates credential databases (e.g., Chrome\
MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.(Citation: ESET MirrorFace DEC 2022)