MirrorStealer — Malware Profile
MirrorStealer is a credential stealer that has been used by MirrorFace since at least 2022 to steal credentials from various applications, including browsers and email clients. MirrorStealer has been delivered directly into system memory via commands issued by LODEINFO.
MITRE ATT&CK techniques (4)
- T1074.001 Local Data Staging
- T1552.006 Group Policy Preferences
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers