MirageFox is a Windows remote access trojan associated with the China-linked espionage group APT15. It is assessed to be an upgraded descendant of the older Mirage RAT and shares code lineage with Mirage and Reaver, indicating continued tool evolution and reuse within APT15 operations. The malware has been linked to espionage activity against sensitive targets, including government, military, and contractor environments.
MirageFox is designed for post-compromise remote control. It gathers basic host information such as the current username, CPU details, and system architecture, decrypts embedded command-and-control configuration data, and then opens a backdoor to receive operator tasking. Supported functionality includes executing commands through the Windows command shell, launching additional processes, modifying files, terminating itself, and waiting for interactive commands from its controllers. Its configuration handling includes decryption of embedded C2 parameters and campaign metadata.
Execution has been associated with DLL hijacking or DLL side-loading, specifically by masquerading as a library expected by a legitimate McAfee executable. This tradecraft aligns with broader APT15 use of legitimate software and hijacked loading paths to evade detection and blend into victim environments. No built-in persistence mechanism is confirmed in the analyzed module itself, suggesting it may be deployed as one component within a larger intrusion set where persistence is established elsewhere.
MirageFox appears tailored for hands-on-keyboard espionage operations in already-compromised networks rather than broad commodity distribution. Available reporting did not establish a confirmed initial infection vector for the malware itself, though APT15 is known to gain access through spearphishing, exploitation of public-facing applications, and abuse of stolen credentials or VPN access in broader campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT15's arsenal includes tools for both Windows (Okrum, MirageFox) and Android
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MirageFox is an upgraded remote access trojan (RAT) used by APT15 for espionage and data exfiltration.
Windows malware in APT15's toolkit used for covert access and espionage.
Backdoor that can gather the username from the victim machine.
Gathers the username from the victim machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.