MirrorFace
Also reported as Earth Kasha and Operation LiberalFace. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1566.002 2 reports in ATT&CK
- T1001.001 1 report reports only
- T1012 1 report reports only
- T1027.004 1 report reports only
- T1027.007 1 report reports only
- T1027.011 1 report reports only
- T1030 1 report reports only
- T1033 1 report in ATT&CK
- T1036.007 1 report reports only
- T1041 1 report reports only
Show all 51 techniques Show fewer
- T1047 1 report in ATT&CK
- T1053.005 1 report reports only
- T1055 1 report reports only
- T1057 1 report in ATT&CK
- T1059.001 1 report reports only
- T1059.003 1 report in ATT&CK
- T1070.004 1 report in ATT&CK
- T1070.006 1 report reports only
- T1071.001 1 report reports only
- T1082 1 report in ATT&CK
- T1087.002 1 report in ATT&CK
- T1091 1 report reports only
- T1112 1 report reports only
- T1113 1 report reports only
- T1115 1 report reports only
- T1124 1 report reports only
- T1127.001 1 report reports only
- T1132.001 1 report reports only
- T1140 1 report reports only
- T1189 1 report reports only
- T1190 1 report in ATT&CK
- T1204.001 1 report reports only
- T1204.002 1 report in ATT&CK
- T1212 1 report reports only
- T1218 1 report reports only
- T1221 1 report in ATT&CK
- T1547.001 1 report reports only
- T1564.001 1 report reports only
- T1564.003 1 report reports only
- T1564.006 1 report reports only
- T1566.001 1 report in ATT&CK
- T1568.002 1 report reports only
- T1573 1 report reports only
- T1574.001 1 report in ATT&CK
- T1585.002 1 report reports only
- T1585.003 1 report reports only
- T1587.001 1 report in ATT&CK
- T1588.001 1 report reports only
- T1588.002 1 report in ATT&CK
- T1622 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2013-3900 KEV
- CVE-2017-1182
- CVE-2019-18187 KEV
- CVE-2019-9489
- CVE-2020-0986 KEV
- CVE-2020-1380 KEV
- CVE-2020-35730 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2022-26134 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-41040 KEV ransomware
Show all 31 CVEs Show fewer
- CVE-2022-41082 KEV ransomware
- CVE-2022-41091 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-49475
- CVE-2023-23397 KEV
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Stone Panda, APT 10, menuPass
Show all 33 reports Show fewer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Endless Struggle Against APT10_ Insights from LODEINFO v0.6.6 - v0.7.3 Analysis - Researcher Blog - ITOCHU Cyber & Intelligence Inc_
-
Unmasking MirrorFace- Operation LiberalFace targeting Japanese political entities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unmasking MirrorFace- Operation LiberalFace targeting Japanese political entities
-
mpressioncss_ta_report_2019_4.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019_4.pdf
Newest first. Details opens the report in Explore.