MirrorStealer — Malware Profile

MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.

MITRE ATT&CK techniques (4)

Attributed threat actors

Read the full analysis on IntelFusions