43
Techniques
16
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent MirrorFace operations included targets in Central Europe and featured use of LODEINFO, HiddenFace, and UPPERCUT malware.

View MITRE record ↗

Techniques by Tactic (43)
Toolsets (16)
🐛
Malware · Linux, macOS, Windows
🐛
DOWNIISSA S9021
Malware · Windows
🐛
Malware · Windows
🐛
LODEINFO S9020
Malware · Windows
🐛
Malware · Windows
🐛
NOOPLDR S9025
Malware · Windows
🐛
Malware · Windows
🐛
UPPERCUT S0275
Malware · Windows
🔧
BITSAdmin S0190
Tool · Windows
🔧
Net S0039
Tool · Windows
🔧
Nltest S0359
Tool · Windows
🔧
Ping S0097
Tool
🔧
Tasklist S0057
Tool
🔧
Wevtutil S0645
Tool · Windows
🔧
ipconfig S0100
Tool
🔧
nbtstat S0102
Tool
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑