G1054 · ATT&CK 19.1 group
MirrorFace
[MirrorFace](https://attack.mitre.org/groups/G1054) is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the [menuPass](https://attack.mitre.org/groups/G0045) umbrella based on targeting, tools, and infrastructure overlaps. [MirrorFace](https://attack.mitre.org/groups/G1054) has been active since at least 2019, at first exclusively targeting Japanese organizations across the media, defense, diplomatic, financial, manufacturing, and academic sectors. Subsequent [MirrorFace](https://attack.mitre.org/groups/G1054) operations included targets in Central Europe and featured use of [LODEINFO](https://attack.mitre.org/software/S9020), [HiddenFace](https://attack.mitre.org/software/S9023), and [UPPERCUT](https://attack.mitre.org/software/S0275) malware.(Citation: Kaspersky LODEINFO OCT 2022)(Citation: Kaspersky LODEINFO Part II OCT 2022)(Citation: ESET MirrorFace DEC 2022)(Citation: JPCERT MirrorFace JUL 2024)(Citation: Trend Micro Earth Kasha NOV 2024)(Citation: Trend Micro Earth Kasha Updates APR 2025)
Aliases: Earth Kasha, MirrorFace
Mapped techniques (43)
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idExploitability validation and laboratory exploit engineering
Vulnerability Research & Exploit Development · explicit-idModule 11 — Mobile and thick-client security
Red Team & Offensive Security · explicit-nameModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · explicit-nameModule 4 — Collection Sources
Cyber Threat Intelligence (CTI) · explicit-nameModule 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · explicit-nameModule 6 — The Threat Actor Landscape
Cyber Threat Intelligence (CTI) · explicit-nameModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 10 — Career Path Continuing Education
Cyber Threat Intelligence (CTI) · explicit-nameModule 10 — Laboratories, tool discipline, and reporting
Red Team & Offensive Security · explicit-name