MirageFox is a remote access trojan (RAT) associated with APT15, a China-linked cyber espionage group also tracked as Ke3chang, Vixen Panda, Royal APT, and Playful Dragon. Reporting describes it as an upgraded version of the older Mirage RAT, believed to date to 2012, with code reuse identified between MirageFox, Mirage, and Reaver. It was observed in 2018, including in activity tied to the hack of a US Navy contractor, and is listed among APT15’s Windows malware arsenal alongside Okrum.
High-confidence capabilities described in the source include collecting host information such as the victim username, CPU information, and system architecture; decrypting embedded configuration data containing command-and-control information; opening a backdoor and awaiting operator tasking; executing commands through cmd.exe via CreateProcessA; modifying files; launching processes; and terminating itself. The decrypted configuration was reported to contain the C2 IP or domain, port, binary name, sleep timer, and campaign identifier. One analyzed configuration contained C2 IP 192.168.0.107, port 80, sleep timer 30000, and campaign identifier "Mirage."
The malware was assessed to likely be loaded through DLL hijacking into a legitimate McAfee binary. Specifically, it exports dll_wWinMain, matching an export in the McAfee module vsodscpl.dll, and after execution the module renames itself to sqlsrver.dll. Researchers reported no persistence mechanism in the analyzed module itself. The original infection vector was not determined, but the internal C2 address in the decrypted configuration led researchers to assess that the malware may have been customized for an already-compromised organization, potentially after access via stolen VPN material or an internal foothold.
Known indicators directly mentioned in the content include the export-directory string MirageFox_Server.dat; the export name dll_wWinMain; the renamed DLL sqlsrver.dll; C2 192.168.0.107:80; and sample SHA-256 hashes 28d6a9a709b9ead84aece250889a1687c07e19f6993325ba5295410a478da30a, 97813e76564aa829a359c2d12c9c6b824c532de0fc15f43765cf6b106a32b9a5, and b7c1ae10f3037b7645541acb9f7421312fb1e164be964ee7acd6eb1299d6acb2.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT15's arsenal includes tools for both Windows (Okrum, MirageFox) and Android
10 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MirageFox is an upgraded remote access trojan (RAT) used by APT15 for espionage and data exfiltration.
Windows malware in APT15's toolkit used for covert access and espionage.
Malware that can gather the username from the victim machine.
MirageFox is a remote access trojan attributed with high confidence to APT15. It appears to be an upgraded Mirage variant, using code reuse from Mirage and Reaver. It collects host information, decrypts embedded C2 configuration, opens a backdoor, waits for C2 commands, executes remote shell commands, modifies files, launches processes, and may use DLL hijacking for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.