MirrorFace, also known as Earth Kasha, is a China-aligned cyberespionage group assessed as a subgroup of APT10. Active since at least 2019, it has primarily targeted Japanese government and political entities, diplomatic and academic institutions, think tanks, media organizations, and defense-related, high-technology, and manufacturing organizations. In 2024, it expanded its known victimology to a Central European diplomatic institute in Operation AkaiRyū, using Expo 2025-themed and diplomatic lures. MirrorFace conducts targeted spear-phishing and has also exploited internet-facing enterprise products. It uses malicious documents, links, and archive-delivered shortcuts to establish execution, and has used DLL side-loading to load the ANEL backdoor. Its tooling includes ANEL, ANELLDR, HiddenFace/NOOPDOOR, customized AsyncRAT, LilimRAT, LODEINFO, and MSRAStealer. HiddenFace supports modular post-compromise activity, encrypted command-and-control communications, passive listener functionality, process injection, scheduled-task execution, and anti-analysis measures. The group has abused Visual Studio Code Remote Tunnels for remote access and command-and-control, and Windows Sandbox to run malware in an isolated environment with reduced host-based visibility. It employs scheduled tasks for persistence, deletes tools and files, clears Windows event logs, uses legitimate executables for DLL side-loading, and collects documents and locally stored browser data. MSRAStealer captures credentials through password-filter and authentication-package abuse. MirrorFace's targeting, tooling overlap with APT10, and use of ANEL support its assessed APT10 lineage. Its operations are assessed to support Chinese state intelligence collection related to national security, foreign policy, and advanced technology interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
71 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
A group linked by multiple researchers to the Chinese APT10 cluster. It abused Windows Sandbox to execute a staged payload chain in an isolated guest environment, evading host-based security visibility, and also abused legitimate Visual Studio Code remote-tunnel capabilities in parallel campaigns.
MirrorFace is listed in the detection's threat-actor annotations.
MirrorFace appears only in the detection's annotations list.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.