Full Report
Cyber-attacks by China-linked MirrorFace targeted Japan’s national security information in major campaigns operating since 2019
Analysis Summary
# Threat Actor: MirrorFace (Earth Kasha)
## Attribution & Identity
Attributed to a China-linked threat actor by Japan’s National Police Agency (NPA) and the National Center of Incident Readiness and Strategy for Cybersecurity (NISC).
Known Aliases: Earth Kasha.
Associated Group: Believed to be a subgroup of the Chinese state-sponsored hacking collective APT10.
## Activity Summary
The actor has been engaged in a prolonged cyber-attack campaign targeting Japanese organizations and individuals since 2019. The primary goal of these attacks is the exfiltration of sensitive information pertaining to Japan’s national security and the theft of advanced technology data.
## Tactics, Techniques & Procedures
- Use of specific malware tools, indicating a consistent operational toolkit.
- **MITRE ATT&CK IDs:** Not explicitly provided in the text, but TTPs noted below suggest information gathering and exfiltration.
## Targeting
- **Sectors:** Organizations and individuals related to Japan’s national security and advanced technology sectors.
- **Geography:** Primarily Japan.
- **Victims:** Japanese organizations and individuals (specific organizational names not provided).
## Tools & Infrastructure
- **Malware families used:** ANEL, LODEINFO, and NOOPDOOR.
- **Infrastructure (C2, domains, IPs):** None explicitly mentioned/defanged in the provided text snippet.
## Implications
The prolonged nature of the campaign (since 2019) and attribution to a suspected state-sponsored group (APT10 subgroup) indicate a highly persistent espionage effort aimed at strategic intelligence collection against Japan. The focus on national security and advanced tech suggests motivations aligned with geopolitical or economic advantage.
## Mitigations
- Enhance detection capabilities against the noted malware families (ANEL, LODEINFO, NOOPDOOR).
- Implement robust information security controls focused on preventing exfiltration of national security and advanced technology data.
- Review and strengthen defenses against known APT10 operational patterns.