logo

MirrorFace Attack against Japanese Organisations

ID: 05d2e7f1-23aa-51b5-badb-07288ed42341

STIX ID: report--05d2e7f1-23aa-51b5-badb-07288ed42341

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2024-07-16

Date Updated: 2026-04-19

Author: 朝長 秀誠 (Shusei Tomonaga)

...
...

**MirrorFace / NOOPDOOR:** JPCERT/CC documents ongoing attacks by the MirrorFace actor targeting Japanese organisations using spearphishing and exploitation of external vulnerabilities (notably Array AG and FortiGate). The report analyzes NOOPDOOR (a shellcode backdoor with XML- and DLL-based loaders called NOOPLDR), its persistence and injection techniques, credential theft methods (LSASS, NTDS.dit, registry hives), lateral movement via SMB/scheduled tasks, data collection/exfiltration, extensive defense-evasion (MSBuild misuse, timestomping, log deletion, disabling Defender), provides IoCs (IPs, IPv6, hashes) and maps observed behavior to MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.