MirrorFace, also tracked as Earth Kasha, is a China-aligned cyber-espionage threat actor assessed as a subgroup within the APT10 umbrella. Active since at least 2019, it has focused primarily on Japanese targets, especially government bodies, political organizations, think tanks, academic institutions, media, diplomatic entities, and defense-adjacent, high-technology, and manufacturing organizations. More recent operations show expansion beyond Japan, including targeting of a Central European diplomatic institute while maintaining a strong Japan-related thematic focus. MirrorFace is characterized by intelligence collection aligned with Chinese state interests rather than financial gain. Its operations commonly begin with highly tailored spearphishing, including impersonation of trusted Japanese political or institutional contacts, malicious attachments or links, and remote-template or VBA-enabled document chains. The actor has also exploited vulnerabilities in internet-facing enterprise products, including SSL-VPN, proxy, and file-transfer appliances, for initial access. Its malware ecosystem includes ANEL, HiddenFace (also known as NOOPDOOR), LODEINFO, MRSAStealer, and customized AsyncRAT variants. MirrorFace has used DLL sideloading loaders such as ANELLDR to decrypt and launch ANEL in memory, and HiddenFace is regarded as a modular backdoor closely associated with this actor. The group also uses a mix of custom tooling and dual-use utilities, including PuTTY, FRP, Rubeus, Cobalt Strike, MSBuild, WMI, PowerShell, and cmd.exe. In later operations it abused Visual Studio Code Remote Tunnels for stealthy remote access and tool delivery. Post-compromise activity includes file and directory discovery, domain and trust enumeration, collection of documents and emails, harvesting of browser-stored data, credential theft through password-filter mechanisms, staging of collected material on victim systems, and exfiltration via protocols and channels such as SCP, SFTP, and RDP. MirrorFace has also been observed using signed binaries and abusing digital-signature trust mechanisms to facilitate sideloading and evade scrutiny. Defense evasion and anti-forensics are prominent in MirrorFace tradecraft. Reported behaviors include disabling Windows Defender, modifying host firewall settings, using Base64-encoded shellcode, deleting malware, tools, archives, and working directories, and clearing Windows event logs. The actor has also executed malware inside Windows Sandbox in some operations to reduce detection and complicate forensic analysis.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
75 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber-espionage operations focused for years on Japanese government, political, think tank, academic, media, defense-adjacent, high-tech, and manufacturing targets, then expanded in late 2024 to a European diplomatic institute. The group uses targeted spear-phishing and exploitation of internet-facing enterprise products, DLL side-loading, ANEL/ANELLDR, HiddenFace/NOOPDOOR, customized AsyncRAT, Visual Studio Code Remote Tunnels, and anti-forensics such as deleting tools and clearing Windows event logs.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Conducting spearphishing-led intrusion and espionage activity, including credential theft, malware deployment, data collection, staging, and exfiltration. The group uses custom malware and public tools, exploits Fortigate and Array AG devices for initial access, and employed multiple post-compromise discovery, credential dumping, defense evasion, and lateral movement techniques during Operation AkaiRyū.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.