Threat actor · all actors
MirrorFaceG1054 state
🇨🇳 CN
aka MirrorFace, Earth Kasha
Last updated: 2026-08-20
About this actor
[MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent [MirrorFace](https://attack.mitre.org/groups/G1054) operations included targets in Central Europe and featured use of [LODEINFO](https://attack.mitre.org/software/S9020), [HiddenFace](https://attack.mitre.org/software/S9023), and [UPPERCUT](https://attack.mitre.org/software/S0275) malware.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: Kaspersky LODEINFO Part II OCT 2022)(Citation: ESET MirrorFace DEC 2022)(Citation: JPCERT MirrorFace JUL 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 65 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2023 — 2 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2023-3466 | 6.4 | 8.3 | 0.0304 | 2023-07-19 | see CVE |
CVE-2023-3467 | 6.4 | 8.0 | 0.0210 | 2023-07-19 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1003.003NTDS ↗T1005Data from Local System ↗T1007System Service Discovery ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.008Masquerade File Type ↗T1047Windows Management Instrumentation ↗T1048Exfiltration Over Alternative Protocol ↗T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.002File Transfer Protocols ↗T1074Data Staged ↗T1074.002Remote Data Staging ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1114Email Collection ↗T1114.001Local Email Collection ↗T1190Exploit Public-Facing Application ↗T1204User Execution ↗T1204.002Malicious File ↗T1221Template Injection ↗T1482Domain Trust Discovery ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1556Modify Authentication Process ↗T1556.002Password Filter DLL ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1591Gather Victim Org Information ↗T1614System Location Discovery ↗T1614.001System Language Discovery ↗T1684Social Engineering ↗T1684.001Impersonation ↗T1685Disable or Modify Tools ↗T1685.005Clear Windows Event Logs ↗T1686Disable or Modify System Firewall ↗T1686.003Windows Host Firewall ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 42 / 65 | 65% |
CM-6 | 38 / 65 | 58% |
CM-2 | 36 / 65 | 55% |
SI-3 | 33 / 65 | 51% |
CM-7 | 31 / 65 | 48% |
AC-3 | 26 / 65 | 40% |
CA-7 | 26 / 65 | 40% |
AC-2 | 24 / 65 | 37% |
AC-6 | 23 / 65 | 35% |
SI-7 | 22 / 65 | 34% |
AC-4 | 19 / 65 | 29% |
SC-7 | 19 / 65 | 29% |
AC-5 | 16 / 65 | 25% |
SI-10 | 16 / 65 | 25% |
CM-5 | 15 / 65 | 23% |
Co-occurring actors
- Clop 2 shared CVEs
Similar actors
Overlapping CVEs
- Clop 0.67
Active in same years
- Cinnamon Tempest 1.00
- Akira 1.00
- Clop 1.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00