Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors MirrorFace

Also known as: Earth Kasha

Description

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: Kaspersky LODEINFO Part II OCT 2022)(Citation: ESET MirrorFace DEC 2022)(Citation: JPCERT MirrorFace JUL 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)

AI Analysis

· 1 week ago

Executive Summary

MirrorFace is a cyberespionage threat actor linked to the People's Republic of China (PRC), operating under the menuPass umbrella group. Active since at least 2019, MirrorFace primarily targets Japanese organizations across media, defense, diplomacy, finance, manufacturing, and academia, with recent operations expanding to Central Europe. The group employs a sophisticated array of malware, including LODEINFO, HiddenFace, UPPERCUT, and Cobalt Strike, to conduct cyberespionage campaigns.

Goals & Targeting

MirrorFace's primary objective appears to be cyberespionage, targeting sectors with significant economic, political, and strategic value. The group's focus on Japanese organizations suggests a particular interest in intelligence related to defense, technology, and diplomatic activities. Expansion into Central Europe indicates a broader strategic goal of gathering情报 from diverse regions. Typical victims include government agencies, academic institutions, financial institutions, and manufacturing companies.

Enhanced Description

MirrorFace, also known as Earth Kasha, is a subgroup operating under the menuPass umbrella, sharing similarities in targeting, tools, and infrastructure. The group has been active since at least 2019, initially focusing on Japanese organizations across multiple sectors. Over time, its operations expanded to include targets in Central Europe. MirrorFace's campaign patterns involve the use of malware such as LODEINFO, HiddenFace, UPPERCUT, and Cobalt Strike, which have been linked to various cyberespionage activities. The group's tactics include spear-phishing, malicious file distribution, and the deployment of custom malware to compromise systems and extract sensitive information.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Custom malware development (LODEINFO, HiddenFace, UPPERCUT)
  • Use of Cobalt Strike for attacks
  • Spear-phishing campaigns
  • Malicious file distribution
  • Credential theft and persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Defense Evasion
Discovery
Lateral Movement
Exfiltration
Collection

ATT&CK Techniques

T1059.003
T1087.002
T1003.002
T1114.001
T1036.008
T1587.001
T1204.002
T1686.003
T1566.001
T1574.001
T1553.002
T1005
T1591
T1071.002
T1588.002
T1614.001
T1685.005
T1482
T1083
T1048.002
T1070.004
T1016
T1221
T1059.005
T1684.001

Software / Tooling

LODEINFO
HiddenFace
UPPERCUT
Cobalt Strike
ROAMINGHOUSE
MirrorStealer
NOOPLDR

Campaigns & Victims

MirrorFace has been involved in several notable campaigns, including Operation AkaiRyū, which targeted Japanese entities and utilized the ANEL backdoor. The group's operations demonstrate a focus on long-term access and data exfiltration. MirrorFace's recent activities suggest an increasing interest in European targets, possibly to gather intelligence beyond its initial geographic concentration in Japan.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over onion domains
  • Exfiltration using file transfer protocols (e.g., FTP)
  • Use of encrypted/encoded files for data storage and transmission
  • Malicious file downloads from specific IPs

Recommended Actions

  • Implement robust email filtering to detect and block spear-phishing attempts.
  • Monitor for unusual process activity indicative of Cobalt Strike and other APT tools.
  • Deploy endpoint detection and response (EDR) solutions to identify malicious behavior patterns.
  • Conduct regular vulnerability assessments to patch systems against known exploitation techniques.
  • Enhance network monitoring for fast-flux DNS and suspicious file transfers.
  • Educate employees on phishing attack vectors through regular security awareness training.

Suggested Tags

APT
cyberespionage
China-aligned
Japan
Central Europe

Confidence Assessment

Confidence in MirrorFace's activities and attributes is high, supported by multiple credible intelligence reports from Kaspersky, ESET, JPCERT, and Trend Micro. However, certain aspects of the group's operational tactics and motivations remain unclear, particularly regarding its long-term strategy and potential affiliations outside the menuPass umbrella.

ATT&CK Techniques

Defense impairment
5 techniques
Discovery
10 techniques
Execution
4 techniques
Stealth
6 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 14 IPv4 Address 4 Domain 2

References

  1. ESET MirrorFace DEC 2022 — Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.
  2. Trend Micro Earth Kasha Updates APR 2025 — Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.
  3. Kaspersky LODEINFO OCT 2022 — Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part I. Retrieved April 17, 2026.
  4. Kaspersky LODEINFO Part II OCT 2022 — Ishimaru, S. (2022, October 31). APT10: Tracking down LODEINFO 2022, part II. Retrieved April 17, 2026.
  5. JPCERT MirrorFace JUL 2024 — Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.
  6. Trend Micro Earth Kasha NOV 2024 — Trend Micro. (2024, November 19). Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella. Retrieved April 17, 2026.

Intel Summary

43

Techniques

9

Tools

2

Campaigns

21

IOCs

0

Observed Data

12

Tactics

Tags

APT
Government Targeting
cyberespionage
China-aligned
Japan
Central Europe

Details

MITRE ID
G1054
Type
Unknown
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--8cf6e33b-b6ef-4a1f-a77c-0ecdde93161f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.