Weeks before the Council of Representatives elections in July 2022, a hacking group known as MirrorFace launched an attack on Japanese politicians using a new credential‑stealing system called “MirrorStealer”.
See also: Uber once again fell victim to a data breach

ESET analysts uncovered the campaign because the hackers left traces behind.
The hackers used the new information-stealing malware MirrorStealer in combination with the LODEINFO backdoor, which communicates with a C2 server known as part of the APT10 network.
In October 2022, Kaspersky published a report on extensive deployment of the LODEINFO backdoor against certain high-profile Japanese targets.
See also: Microsoft: Fixes bug that allows ransomware installation
Spearphishing attacks
On June 29, 2022, the hacking group MirrorFace (APT10 and Cicada) launched a spear-phishing scam by sending email messages to its targets, pretending to be representatives of the recipient's political party. The message contained an attached file with video files that asked them to publish it on social networking platforms.

In some cases, the attackers pretended to be a Japanese government agency and included deceptive documents that secretly downloaded WinRAR files without the user's knowledge.
The file contained an encrypted copy of the malicious software LODEINFO, a malicious DLL loading program, and a benign application (K7Security Suite) that is used to bypass DLL search order commands.
This evolution of the attack is identical to the one described by Kaspersky in its previous report and deploys the backdoor directly into RAM memory.
The malicious activities of MirrorStealer
To achieve its malicious goals, APT10 leveraged LODEINFO to develop MirrorStealer (‘31558_n.dll’) on compromised systems worldwide.
MirrorStealer is a malicious program that searches for sensitive data stored in web browsers and email clients, including the widely used Japanese program ‘Becky!’.
This shows that MirrorStealer may have been specifically designed for APT10’s operations focusing on Japan.
MirrorStealer stores all stolen credentials in a temporary txt file, waiting for LODEINFO to transfer them to the Command-and-Control (C2) server, as it does not have its own data exfiltration capabilities.
LODEINFO is the link that bridges the C2 and MirrorStealer—retransmitting commands to the info-stealer.

ESET security experts discovered that LODEINFO used commands to load MirrorStealer into the memory of the compromised system and inject it into a newly created cmd.exe process, executing it immediately thereafter.
Furthermore, evidence shows that the remote operator initially tried to steal browser cookies using MirrorStealer, but was forced to change strategy and use LODEINFO, because this new info-stealer cannot perform such tasks.
See also: HTML smuggling technique uses SVG files and distributes QBot
APT10 was not as meticulous in this campaign, leaving the MirrorStealer credential file behind on the compromised computers. As expected, their approach resulted in all traces of their activity remaining on those systems.
APT 10 is a sophisticated Chinese threat actor that has been active since 2009. The group has targeted government agencies and technology companies around the world, seeking valuable information that they can use for political espionage or intelligence gathering purposes. Organizations should be aware of the risks posed by APT10 attacks so that they can take proactive steps to protect themselves, including best practices for cybersecurity measures, such as strong password policies , deploying two-factor authentication where possible, etc. In addition, it is important to stay informed of any new threats posed by this threat actor so that they can adjust their security measures accordingly, if necessary.
Information source: bleepingcomputer.com
