Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1054
MITRE ATT&CK Group

MirrorFace (G1054)

Earth Kasha
ShareXLinkedInRedditHN

[MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent [MirrorFace](https://attack.mitre.org/groups/G1054) operations included targets in Central Europe and featured use of [LODEINFO](https://attack.mitre.org/software/S9020), [HiddenFace](https://attack.mitre.org/software/S9023), and [UPPERCUT](https://attack.mitre.org/software/S0275) malware.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: Kaspersky LODEINFO Part II OCT 2022)(Citation: ESET MirrorFace DEC 2022)(Citation: JPCERT MirrorFace JUL 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)

▪Techniques used (43)

T1566.002Spearphishing LinkT1057Process DiscoveryT1686.003Windows Host FirewallT1074.002Remote Data StagingT1685Disable or Modify ToolsT1087.002Domain AccountT1614.001System Language DiscoveryT1591Gather Victim Org InformationT1090ProxyT1685.005Clear Windows Event LogsT1021.001Remote Desktop ProtocolT1587.001MalwareT1070.004File DeletionT1003.002Security Account ManagerT1083File and Directory DiscoveryT1482Domain Trust DiscoveryT1684.001ImpersonationT1588.002ToolT1003.001LSASS MemoryT1204.002Malicious FileT1018Remote System DiscoveryT1016System Network Configuration DiscoveryT1553.002Code SigningT1005Data from Local SystemT1059.003Windows Command ShellT1566.001Spearphishing AttachmentT1059.005Visual BasicT1007System Service DiscoveryT1082System Information DiscoveryT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1574.001DLLT1021.002SMB/Windows Admin SharesT1071.002File Transfer ProtocolsT1190Exploit Public-Facing ApplicationT1036.008Masquerade File TypeT1003.003NTDST1560.001Archive via UtilityT1221Template InjectionT1556.002Password Filter DLLT1047Windows Management InstrumentationT1114.001Local Email CollectionT1027.013Encrypted/Encoded FileT1033System Owner/User Discovery

▪Software used (16)

S0039NettoolS0154Cobalt StrikemalwareS9022MirrorStealermalwareS0275UPPERCUTmalwareS0359NltesttoolS0190BITSAdmintoolS0057TasklisttoolS0100ipconfigtoolS9020LODEINFOmalwareS9026ROAMINGHOUSEmalwareS9021DOWNIISSAmalwareS0102nbtstattoolS9023HiddenFacemalwareS0097PingtoolS0645WevtutiltoolS9025NOOPLDRmalware
G1054on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.