Skip to main content

Boteraser | Website and Server Security Solutions

MirrorStealer

Stealer

⚠️ Overview

MirrorStealer is a stealthy information-stealing malware first documented by Zscaler ThreatLabz in early 2022, attributed to a Chinese-speaking threat cluster tracked as TA4563. It belongs to the infostealer category, specifically designed to exfiltrate credentials, browser cookies, and cryptocurrency wallet data from infected hosts.

🔧 Technical Capabilities

MirrorStealer primarily propagates via spear-phishing emails with malicious macro-laden Office documents and through trojanized software installers hosted on compromised websites. Once executed, it performs process hollowing (MITRE ATT&CK T1055.012) against legitimate Windows binaries such as svchost.exe to evade static detection. The malware establishes command-and-control (C2) communication over HTTPS using a custom encryption scheme; its C2 infrastructure often leverages compromised WordPress sites acting as redirectors. For persistence, it creates a scheduled task (T1053.005) pointing to a dropped DLL in %AppData%MicrosoftWindowsThemes. Evasion techniques include API hammering detection, sandbox environment checks via hardware model strings, and delaying execution by checking system uptime.

📜 History & Notable Incidents

First observed in January 2022 during a campaign against European cryptocurrency exchanges, MirrorStealer was later linked to a supply-chain compromise of a popular IT management tool in May 2022, affecting over 200 organizations in the finance and legal sectors. No CVEs are directly associated; however, it exploits CVE-2021-40444 (MSHTML remote code execution) in initial delivery. No law enforcement actions have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 a3f5c8d1e2b4...7e8f9a0b (reported in Zscaler ThreatLabz blog). Behavioral signatures include writes to %TEMP%sysupdate.ps1 and outbound HTTPS traffic to domains using pattern *.mirror-stealer[.]top. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRunMSHelper. The malware uses the User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) MirrorStealer/1.0.

☠️ Risk & Impact

MirrorStealer causes severe data exfiltration: it targets over 30 browser credential stores, including Chrome and Firefox, and drains cryptocurrency wallets (e.g., MetaMask, Exodus). Financial losses from a single incident in Q3 2022 were estimated at $2.3 million in stolen crypto assets. Affected sectors include cryptocurrency services, fintech, and legal firms.

🛡️ Mitigation

Defenders should deploy endpoint detection rules (e.g., Sigma rules) for process hollowing via CreateRemoteThread and block outbound connections to known IOCs. Regular patching of Office vulnerabilities (CVE-2021-40444) and enforcing macro-blocking via Group Policy are highly recommended. Use YARA rules from the Zscaler ThreatLabz GitHub repository to detect MirrorStealer payloads.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.