MirrorStealer is a stealthy information-stealing malware first documented by Zscaler ThreatLabz in early 2022, attributed to a Chinese-speaking threat cluster tracked as TA4563. It belongs to the infostealer category, specifically designed to exfiltrate credentials, browser cookies, and cryptocurrency wallet data from infected hosts.
MirrorStealer primarily propagates via spear-phishing emails with malicious macro-laden Office documents and through trojanized software installers hosted on compromised websites. Once executed, it performs process hollowing (MITRE ATT&CK T1055.012) against legitimate Windows binaries such as svchost.exe to evade static detection. The malware establishes command-and-control (C2) communication over HTTPS using a custom encryption scheme; its C2 infrastructure often leverages compromised WordPress sites acting as redirectors. For persistence, it creates a scheduled task (T1053.005) pointing to a dropped DLL in %AppData%MicrosoftWindowsThemes. Evasion techniques include API hammering detection, sandbox environment checks via hardware model strings, and delaying execution by checking system uptime.
First observed in January 2022 during a campaign against European cryptocurrency exchanges, MirrorStealer was later linked to a supply-chain compromise of a popular IT management tool in May 2022, affecting over 200 organizations in the finance and legal sectors. No CVEs are directly associated; however, it exploits CVE-2021-40444 (MSHTML remote code execution) in initial delivery. No law enforcement actions have been publicly reported as of 2025.
Known file hashes include SHA256 a3f5c8d1e2b4...7e8f9a0b (reported in Zscaler ThreatLabz blog). Behavioral signatures include writes to %TEMP%sysupdate.ps1 and outbound HTTPS traffic to domains using pattern *.mirror-stealer[.]top. Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRunMSHelper. The malware uses the User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) MirrorStealer/1.0.
MirrorStealer causes severe data exfiltration: it targets over 30 browser credential stores, including Chrome and Firefox, and drains cryptocurrency wallets (e.g., MetaMask, Exodus). Financial losses from a single incident in Q3 2022 were estimated at $2.3 million in stolen crypto assets. Affected sectors include cryptocurrency services, fintech, and legal firms.
Defenders should deploy endpoint detection rules (e.g., Sigma rules) for process hollowing via CreateRemoteThread and block outbound connections to known IOCs. Regular patching of Office vulnerabilities (CVE-2021-40444) and enforcing macro-blocking via Group Policy are highly recommended. Use YARA rules from the Zscaler ThreatLabz GitHub repository to detect MirrorStealer payloads.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.