Also known as: Earth Kasha
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: Kaspersky LODEINFO Part II OCT 2022)(Citation: ESET MirrorFace DEC 2022)(Citation: JPCERT MirrorFace JUL 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)
Executive Summary
MirrorFace is a cyberespionage threat actor linked to the People's Republic of China (PRC), operating under the menuPass umbrella group. Active since at least 2019, MirrorFace primarily targets Japanese organizations across media, defense, diplomacy, finance, manufacturing, and academia, with recent operations expanding to Central Europe. The group employs a sophisticated array of malware, including LODEINFO, HiddenFace, UPPERCUT, and Cobalt Strike, to conduct cyberespionage campaigns.
Goals & Targeting
MirrorFace's primary objective appears to be cyberespionage, targeting sectors with significant economic, political, and strategic value. The group's focus on Japanese organizations suggests a particular interest in intelligence related to defense, technology, and diplomatic activities. Expansion into Central Europe indicates a broader strategic goal of gathering情报 from diverse regions. Typical victims include government agencies, academic institutions, financial institutions, and manufacturing companies.
Enhanced Description
MirrorFace, also known as Earth Kasha, is a subgroup operating under the menuPass umbrella, sharing similarities in targeting, tools, and infrastructure. The group has been active since at least 2019, initially focusing on Japanese organizations across multiple sectors. Over time, its operations expanded to include targets in Central Europe. MirrorFace's campaign patterns involve the use of malware such as LODEINFO, HiddenFace, UPPERCUT, and Cobalt Strike, which have been linked to various cyberespionage activities. The group's tactics include spear-phishing, malicious file distribution, and the deployment of custom malware to compromise systems and extract sensitive information.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
MirrorFace has been involved in several notable campaigns, including Operation AkaiRyū, which targeted Japanese entities and utilized the ANEL backdoor. The group's operations demonstrate a focus on long-term access and data exfiltration. MirrorFace's recent activities suggest an increasing interest in European targets, possibly to gather intelligence beyond its initial geographic concentration in Japan.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in MirrorFace's activities and attributes is high, supported by multiple credible intelligence reports from Kaspersky, ESET, JPCERT, and Trend Micro. However, certain aspects of the group's operational tactics and motivations remain unclear, particularly regarding its long-term strategy and potential affiliations outside the menuPass umbrella.
No observed data linked yet.
43
Techniques
9
Tools
2
Campaigns
21
IOCs
0
Observed Data
12
Tactics