MirrorFace — APT Profile

MirrorFace is a China-linked APT targeting Japanese government, politicians, think tanks, and media. Japan National Police Agency attributed campaigns in 2024. Uses LODEINFO and NOOPDOOR backdoors. Notable for spear-phishing impersonating Japanese political figures.

Also tracked as

Earth Kasha

Tools & malware

Vendor research

Read the full analysis on IntelFusions