MirrorFace — APT Profile
MirrorFace is a China-linked APT targeting Japanese government, politicians, think tanks, and media. Japan National Police Agency attributed campaigns in 2024. Uses LODEINFO and NOOPDOOR backdoors. Notable for spear-phishing impersonating Japanese political figures.Also tracked as
Earth Kasha
Tools & malware
- ANEL Backdoor
- HiddenFace Backdoor
- LODEINFO Backdoor
- NOOPDOOR Backdoor
Vendor research
- Spot the Difference: Earth Kasha's New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella Trend Micro
- APT10: Tracking down LODEINFO 2022, part I Ishimaru, S
- APT10: Tracking down LODEINFO 2022, part II Ishimaru, S
- MirrorFace Attack against Japanese Organisations Tomonaga, S
- Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities Breitenbacher, D
- MirrorFace Cyberattack Campaign Attribution Japan NPA
- Earth Kasha (MirrorFace) Updates TTPs Trend Micro
- MirrorFace: Unmasking the Connection Between China and Japan-Targeted Attacks ESET