Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:33:10 UTC Home > List all groups > List all tools > List all groups using tool MirrorStealer Tool: MirrorStealer Names MirrorStealer Category Malware Type Credential stealer Description (ESET) MirrorStealer, internally named 31558_n.dll by MirrorFace, is a credential stealer. To the best of our knowledge, this malware has not been publicly described. In general, MirrorStealer steals credentials from various applications such as browsers and email clients. Interestingly, one of the targeted applications is Becky!, an email client that is currently only available in Japan. All the stolen credentials are stored in %TEMP%\31558.txt and since MirrorStealer doesn’t have the capability to exfiltrate the stolen data, it depends on other malware to do it. Information Last change to this tool card: 27 December 2022 Download this tool card in JSON format All groups using tool MirrorStealer Changed Name Country Observed APT groups Operation LiberalFace, MirrorFace 2019-Aug 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5826f248-287f-4b28-a5fe-03a46ee71957 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5826f248-287f-4b28-a5fe-03a46ee71957 Page 1 of 1