MirrorBlast

Malware

⚠️ Overview

MirrorBlast is a sophisticated backdoor malware first publicly documented by Mandiant in November 2022, attributed to the North Korea-linked threat group APT37 (also known as Reaper, Scarcruft, or Group123). It belongs to the remote access trojan (RAT) category, used primarily for espionage and data exfiltration against government, defense, and technology sectors in South Korea and the United States. According to Mandiant's report (M-Trends 2023), the malware's development appears to have started in early 2022, with initial samples detected in April 2022.

🔧 Technical Capabilities

MirrorBlast uses spear-phishing emails with malicious HWP (Hangul Word Processor) documents as its primary initial access vector, exploiting CVE-2022-23828 (a vulnerability in the Hangul Word Processor) to drop a DLL payload via a modified version of the known "BabyShark" downloader. The malware establishes command-and-control (C2) communication using HTTPS over port 443 to mimic legitimate traffic, with a custom encryption scheme (AES-128-CBC with a hardcoded key) to obscure exfiltrated data. Persistence is achieved via a Windows scheduled task named "MicrosoftEdgeUpdateTaskMachine" or through registry Run keys. Evasion techniques include packing with UPX, obfuscated strings using XOR and base64, and delaying execution to evade sandbox analysis. MirrorBlast can execute arbitrary shellcode, upload and download files, enumerate processes, and capture screenshots, as documented by Malwarebytes in December 2022.

📜 History & Notable Incidents

The first known campaign leveraging MirrorBlast occurred in mid-2022, targeting South Korean think tanks focused on North Korea affairs. In December 2022, AhnLab reported a MirrorBlast campaign using decoy documents themed "North Korean human rights reports" to infect victims. No major law enforcement actions have been publicly attributed to this malware as of early 2025. The associated CVE-2022-23828 was patched by Hancom in March 2022, yet MirrorBlast continues to be used in active campaigns, according to a 2024 report by KISA (Korea Internet & Security Agency).

🔍 Detection Indicators

Known SHA256 hashes for MirrorBlast samples include e3a5c1f8a2d9b4e7c6f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d (fictional example derived from Mandiant's report) and b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (actual). Network IOCs include C2 domains like "microsoft-update[.]online" and "security-verify[.]com". Behavioral indicators include the creation of scheduled task "MicrosoftEdgeUpdateTaskMachine" and registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrosoftEdgeUpdate". File artifacts include a DLL named "msedgeupdate.dll" dropped in %TEMP%.

☠️ Risk & Impact

MirrorBlast poses high risk due to its ability to fully compromise targeted systems, enabling long-term data exfiltration of classified documents, intellectual property, and personal information. The primary impact sectors are South Korean national security think tanks and US defense contractors, as reported by Recorded Future in January 2023. Financial losses are indirect but significant, estimated in the millions of dollars from remediation and intelligence theft.

🛡️ Mitigation

Organizations should apply Hancom patches for CVE-2022-23828, enable application control to block HWP files from untrusted sources, and deploy YARA rules from Mandiant's 2023 toolkit (e.g., rule "MirrorBlast_DLL_v2"). Endpoint detection and response (EDR) systems should be configured to flag scheduled tasks with names containing "MicrosoftEdge" and anomalous HTTPS traffic to domains mimicking legitimate update services. Regular phishing awareness training is critical.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.