MirrorFace, also known as Earth Kasha, is a China-aligned cyberespionage intrusion set assessed as a subgroup of APT10. Active since at least 2019, it has primarily targeted Japanese government and political entities, diplomatic and academic institutions, think tanks, media, and defense-, high-technology-, and manufacturing-related organizations. In 2024, Operation AkaiRyū expanded its known victimology to a Central European diplomatic institute using Expo 2025-themed lures. MirrorFace conducts intelligence collection aligned with Chinese national-security, foreign-policy, and advanced-technology interests. MirrorFace commonly obtains access through targeted spear-phishing, including impersonation of Japanese political organizations, malicious documents, links, and archives. It has also exploited internet-facing enterprise appliances. The group has used DLL side-loading to execute ANELLDR and load the ANEL backdoor in memory, and has deployed HiddenFace (also called NOOPDOOR), customized AsyncRAT, LilimRAT, and earlier LODEINFO malware. It has abused Visual Studio Code Remote Tunnels for encrypted remote access and command-and-control operations. MirrorFace has demonstrated substantial defense-evasion tradecraft, including use of signed legitimate executables for side-loading, deletion of tools and dropped files, Windows event-log clearing, process injection, and malware execution within Windows Sandbox. Its sandbox operations use hidden or scheduled sandbox sessions, mapped host folders, and Tor-routed command-and-control communications. HiddenFace supports modular execution, encrypted communications, persistence through scheduled tasks and registry-stored payloads, and injection into legitimate Windows processes. MirrorFace has also used credential-stealing capabilities to capture authentication material and collected locally stored documents, browser data, and other intelligence-relevant information for exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
70 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A group linked by multiple researchers to the Chinese APT10 cluster. It abused Windows Sandbox to execute a staged payload chain in an isolated guest environment, evading host-based security visibility, and also abused legitimate Visual Studio Code remote-tunnel capabilities in parallel campaigns.
MirrorFace appears only in the detection's annotations list.
Listed in the detection's APT annotations.
Listed in the detection's Annotations section.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.