Mirrorface

Threat Actor updated 6 months ago (2024-11-29T13:57:49.947Z)
Download STIX
Preview STIX
MirrorFace is a threat actor group known for its focus on Japanese hackers. The group has been particularly active in the cybersecurity landscape, with a history of malicious activities aimed at compromising systems and stealing valuable information. However, over the summer, Eset researchers discovered that MirrorFace had expanded its operations beyond Japan, targeting a diplomatic organization within the European Union. This marked the first time that Eset detected the threat actor group directing its efforts towards a European organization, signaling a significant shift in its operational strategy. Among Chinese users of SoftEther VPN or a SoftEther VPN bridge, three notable groups have been identified: Flax Typhoon (also known as RedJuliett), Gallium, and MirrorFace (also known as Earth Kasha). These groups have been implicated in various cyber espionage activities. For instance, Flax Typhoon was caught spying on Taiwanese firms, while Gallium unleashed stealthy LuaJIT-based malware. MirrorFace, on the other hand, zeroed in on Japan's manufacturing sector, causing significant disruptions and potentially leading to substantial financial losses. Despite this new geographic targeting, MirrorFace remains primarily focused on Japan and events related to it, according to Eset. This suggests that while the threat actor group is diversifying its targets, its primary interest remains rooted in Japan. This continued focus on Japan underscores the need for organizations in the country, especially those in the manufacturing sector, to bolster their cybersecurity measures to mitigate potential threats from MirrorFace and similar threat actors.
Description last updated: 2024-11-08T00:03:05.986Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Earth Kasha is a possible alias for Mirrorface. Earth Kasha, a recognized threat actor in the cybersecurity landscape, has been notorious for its malicious activities primarily targeting individuals and organizations in Japan. Utilizing spear-phishing emails as the primary intrusion vector, Earth Kasha conducted campaigns until early 2023, primar
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Vpn
Apt
Tool
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Mirrorface Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more