HiddenFace, also known as NOOPDOOR, is a modular Windows backdoor associated exclusively with the China-aligned espionage group MirrorFace, which is widely linked to the APT10 umbrella. It represents a more advanced successor to MirrorFace’s earlier tooling and has been used in intrusions targeting Japanese organizations and, by 2024, at least one European diplomatic target. MirrorFace operations using HiddenFace have focused on intelligence collection against government, political, diplomatic, think tank, academic, media, defense, high-technology, and manufacturing entities.
HiddenFace is designed for stealth, modular expansion, and long-term access on compromised systems. It has been deployed as a later-stage implant after initial compromise through spearphishing or exploitation of internet-facing enterprise products, and has also been observed following earlier MirrorFace malware such as LODEINFO or alongside ANEL and a customized AsyncRAT. Installation has involved scheduled-task execution, use of MSBuild with malicious project files, a dedicated loader known as FaceXInjector or NOOPLDR, encrypted payload storage, and process injection into legitimate Windows utilities. The malware uses machine-specific encryption tied to host characteristics, dynamically resolves APIs, restricts DLL loading to Microsoft-signed libraries, checks for security and analysis tools, and employs randomized sleep behavior and single-instance controls to reduce detection.
The backdoor supports both built-in and externally supplied modules, with external components encrypted and derived from host-specific values. It can identify processes associated with security software, alter directory timestamps for anti-forensics, and maintain persistence on compromised machines. HiddenFace communicates with command-and-control infrastructure over a custom protocol using TCP port 443, encrypting initial session material with RSA-2048 before switching to symmetric ciphers. It also supports passive communications by listening on configured ports and modifying host firewall settings to permit access.
HiddenFace has been used as part of broader MirrorFace post-compromise activity that included remote access, tool deployment, document collection, and exfiltration of locally stored data of intelligence value. It has also been linked to exfiltration of credentials harvested by the related MSRAStealer component. Its exclusive use by MirrorFace, combined with its modular architecture and anti-analysis features, makes it one of the most distinctive and sophisticated malware families in that group’s arsenal.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group also deploys HiddenFace (aka NOOPDOOR), a modular backdoor observed only in MirrorFace operations, alongside a heavily customised version of AsyncRAT for additional control.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Performs few defensive actions ... Removes API resolution code → Memory dump is malformed
HiddenFace dynamically resolves the necessary APIs upon its startup.
HiddenFace is stored in a registry key on the compromised machine.
External modules ... Stored in a file – AES-256-CBC-encrypted ... Collected credentials are dumped into msra.tlb – AES-256-CBC encrypted
FaceXInjector is used to inject HiddenFace into a legitimate Windows utility.
Once HiddenFace is moved to the registry, the file in which it was delivered is deleted.
HiddenFace reads external modules from an AES-encrypted file.
Periodically checks running processes against a list of blacklisted applications • Debuggers, process monitors, network analysis tools …
HiddenFace queries the registry for machine-specific information such as the machine ID.
HiddenFace determines the currently logged in user’s name and sends it to the C&C server.
HiddenFace gathers various system information and sends it to the C&C server.
Example 1 – “Exfiltrate a file” command ... Name of the file to exfiltrate ... Base directory if the filename is relative ... Known file size ... Known last write time
HiddenFace determines the system time and sends it to the C&C server.
Periodically checks running processes against a list of blacklisted applications • Debuggers, process monitors, network analysis tools …
Sleeps randomly in between 30 and 60 seconds → Likely to avoid behavioral analysis by sandbox or security solutions
ANEL, HiddenFace and the customised AsyncRAT beacon to C2 over web protocols.
Passive communication ... Hard-coded list of ports to listen on (e.g., 47000)
Additional modules can be sent by an operator ... Module ID not found → Additional temporary module
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Private modular backdoor described as exclusive to MirrorFace operations and used for additional control of compromised systems.
MirrorFace’s flagship modular backdoor, deployed in later stages of attacks for persistence and post-compromise activity. It supports encrypted C2, DGA-based resolution, discovery, clipboard collection, exfiltration, timestomping, registry storage, and anti-debugging features.
Malware that can alter timestamps of directory contents on infected hosts.
Malware that identifies processes associated with security applications and tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.