MirrorBlast is a Windows malware delivery chain and campaign cluster first observed in 2021 and widely associated with the financially motivated TA505 threat actor. It has primarily targeted financial-services organizations, while related activity has also affected a broader set of industries across North America, Europe, Hong Kong, and German-speaking regions. MirrorBlast is commonly used as an intermediate stage that ultimately leads to deployment of FlawedGrace, a remote access trojan strongly linked to TA505 operations.
The infection chain typically begins with phishing emails or file-sharing lures themed around SharePoint, OneDrive, secure documents, invoices, legal notices, health claims, or similar business content. Victims are directed to malicious or compromised landing pages or receive weaponized Excel documents directly. Execution depends on users enabling macros. The Excel stage uses lightweight and obfuscated macro logic, including anti-sandbox and victim-filtering checks, then invokes JScript and hands off execution to msiexec to retrieve and install an MSI package while obscuring the parent-child process chain.
The MSI stage drops a legitimate scripting interpreter together with a malicious script, most notably REBOL- or KiXtart-based loaders. These loaders perform basic host reconnaissance, collecting details such as domain, username, computer name, operating system information, architecture, and in some cases process data. They communicate with command-and-control infrastructure, receive a victim identifier, and poll for instructions or additional payloads. Some observed variants establish persistence through autorun mechanisms. Later stages can download further loaders or shellcode, culminating in FlawedGrace deployment.
MirrorBlast has been linked to TA505 with high confidence by multiple researchers based on its email-to-Excel-to-MSI tradecraft, similarities to TA505 loader patterns such as Get2/GetandGo, lure design, domain naming conventions, staged selective delivery logic, and repeated association with FlawedGrace. The campaign reflects TA505’s pattern of evolving intermediate loaders while preserving a recognizable phishing-led intrusion workflow focused on stealth, modularity, and selective follow-on payload delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Morphisec Labs tracked a new MirrorBlast campaign targeting financial services organizations. MirrorBlast is delivered via a phishing email that contains malicious links which download a weaponized Excel document.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The new loader stages are coded in uncommon scripting languages—Rebol and KiXtart. | In the attack chain, the Excel macros download the first MSI file, which executes the first loader, encoded in KiXtart scripting language.
Once it receives the appropriate response, it will execute a Powershell command that downloads an archive file and extracts its content to a folder named archive.
The Excel document is weaponized with an extremely lightweight macro code.
The command executes JScript through the AddCode method from the ScriptControl ActiveX object.
Additionally, the code has been added one more obfuscation layer on top of the previous obfuscation.
These URLs lead to a compromised SharePoint or a fake OneDrive site that the attackers use to evade detection, in addition to a sign-in requirement (SharePoint) that helps to evade sandboxes.
This spawns the msiexec.exe process, which is responsible for downloading and installing MSI package. It is also a known way to break an attack chain sequence and complicate attack trajectory visibility.
Looking at the strings along with the .pcap file we captured, we see that the script sends the victim’s machine information (domain, computer name, user name, process list) to the C2.
Next, it exfiltrates targeted information by sending a base64 encoded GET request that represents the user domain, username, OS version, architecture, along with a Rebol script build number.
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-delivered malware campaign/toolchain using a weaponized Excel document with a lightweight macro that executes JScript and abuses msiexec to install an MSI, which drops KiXtart or REBOL-based loaders for follow-on payload delivery while evading sandbox and signature-based detection.
MirrorBlast is a phishing-delivered malware campaign using weaponized Excel documents with lightweight macros, anti-sandbox checks, JScript execution, and msiexec to fetch MSI installers that deploy follow-on scripting-based loaders.
A malware campaign/loader chain first observed in late September 2021 that uses malicious Excel lure documents and staged KiXtart and Rebol phases to profile victims, communicate with C2, and selectively deliver additional payloads.
A Rebol-based intermediary loader/downloader used in the TA505 infection chain. It downloads additional Rebol script stagers, which then lead to ReflectiveGnome and ultimately FlawedGrace.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.