A MirrorBlast phishing campaign targeted financial services firms and other organizations across multiple regions using weaponized Excel attachments and SharePoint- or OneDrive-themed lures. Researchers said the infection chain relied on extremely lightweight macros, anti-sandbox checks, and the Windows binary msiexec.exe to retrieve MSI installers while minimizing detection. The MSI files then deployed REBOL- or KiXtart-based loaders that profiled infected hosts, contacted command-and-control infrastructure, and waited for follow-on payloads.
Security researchers linked the activity to TA505 with high confidence based on overlapping tactics, infrastructure, and malware staging patterns. Reported similarities included domain naming conventions, registrar usage, lure formatting, selective victim filtering, and shared infrastructure such as 169.239.128[.]11, alongside parallels with TA505's historical Get2/GetandGo and SDBBot operations. The campaign's use of staged reconnaissance and reported ties to FlawedGrace/GraceWire further strengthened the assessment that MirrorBlast is part of, or closely aligned with, TA505's financially motivated operations.

Get the infrastructure and lures behind it.
11 events from the most recent confirmed update back to the earliest known activity.
HP Wolf Security published an analysis on 19 October 2021 concluding that similarities between MirrorBlast and TA505 Get2/SDBBot operations significantly strengthened the hypothesis that they were linked, though not definitively proven. The assessment cited overlaps in domains, infrastructure, cadence, lure formatting, and staged reconnaissance behavior.
HP reported that a MirrorBlast campaign on 14 October 2021 used the same test document previously seen in a 2020 TA505 campaign. This reuse was presented as another similarity strengthening the TA505 linkage hypothesis.
On 7 October 2021, a MirrorBlast campaign used a download website whose design was almost identical to websites used in TA505 campaigns. HP also noted similar user-agent filtering behavior and lure-document styling.
A MirrorBlast campaign on 4 October 2021 used the domain fidufagios[.]com with command-and-control IP address 169.239.128[.]11. HP identified this as infrastructure overlap with a 2019 TA505 campaign.
Proofpoint reported that TA505's renewed campaigns, which began in early September 2021, grew from several thousand messages per wave to tens or hundreds of thousands of emails by late September and early October. The actor also expanded targeting beyond primarily North America to German-speaking countries including Germany and Austria.
Morphisec reported that the new MirrorBlast campaign it tracked began in early September and targeted financial organizations and other sectors across multiple regions. The campaign used phishing emails with malicious Excel attachments and later SharePoint- and OneDrive-themed lures.
HP reported that MirrorBlast was first observed at the end of September 2021 and that activity increased around that time, with new domains appearing almost daily. Proofpoint Emerging Threats Labs named the malware MirrorBlast based on its command-and-control traffic signatures.
Morphisec said it observed activity related to the MirrorBlast campaign in April 2021. The reference presents this as earlier activity connected to the later campaign cluster.
HP reported that TA505 used a specific test document in a 2020 campaign. The same document was later seen in a MirrorBlast campaign, supporting the suspected linkage between the two.
A TA505 campaign on 9 October 2019 used the domain onedrive-sdn[.]com and the IP address 169.239.128[.]11 for command and control. This infrastructure was later cited as an overlap with MirrorBlast activity.
Morphisec attributed the MirrorBlast campaign to TA505 with high confidence based on the email-to-XLS-to-MSI infection chain, SharePoint/OneDrive lure themes, domain naming patterns, a reused MD5 tied to a prior TA505 intrusion, and reporting that later stages led to FlawedGrace. The campaign used KiXtart- and REBOL-based MSI payloads that profiled victims and awaited further instructions from command-and-control infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 148 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourcethreatresearch.ext.hp.com
Open sourceproofpoint.com
Open sourcelolbas-project.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.