PULSE NAME
Threat Actor Profile: Mirage
WHITE fraevolquez 2025-06-02 Modified: 2025-06-02
95
IOCs
HIGH VOLUME
# Mirage - Threat Actor Profile **Report Date**: 2025-06-02 **Actor Type**: unknown ## Description Mirage is a sophisticated cyber espionage group believed to be linked to Chinas Peoples Liberation Army PLA. The groups primary focus is on intelligence gathering, targeting sectors like aerospace and defense. They employ a variety of tactics and tools, including custom malware. ## Targeted Sectors * Administración pública * Transporte aéreo * Manufactura * Investigación y tecnología espacial * Servicios públicos * ... y 10 más ## Targeted Countries * República Dominicana * India 2 * Ghana * Siria * Venezuela * ... y 61 más
Indicators of Compromise (95)
All CVE hostname domain
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2012-0158 IOC associated with Mirage 2025-06-02
CVE CVE-2015-2546 IOC associated with Mirage 2025-06-02
CVE CVE-2017-11882 IOC associated with Mirage 2025-06-02
CVE CVE-2021-31207 IOC associated with Mirage 2025-06-02
CVE CVE-2021-34473 IOC associated with Mirage 2025-06-02
CVE CVE-2021-34523 IOC associated with Mirage 2025-06-02
hostname 6b4s.popmonster.ru IOC associated with Mirage 2025-06-02
hostname 9356.popmonster.ru IOC associated with Mirage 2025-06-02
domain actuallys.com IOC associated with Mirage 2025-06-02
hostname afg.collinformations.com IOC associated with Mirage 2025-06-02
domain andspurs.com IOC associated with Mirage 2025-06-02
hostname apps.androidupdated.net IOC associated with Mirage 2025-06-02
domain asistechs.com IOC associated with Mirage 2025-06-02
hostname b.popmonster.ru IOC associated with Mirage 2025-06-02
domain baddadsclub.com IOC associated with Mirage 2025-06-02
hostname bat.androidupdated.net IOC associated with Mirage 2025-06-02
domain beltsymd.org IOC associated with Mirage 2025-06-02
domain cancelle.net IOC associated with Mirage 2025-06-02
domain cavanic9.net IOC associated with Mirage 2025-06-02
domain cognacbrown.co.uk IOC associated with Mirage 2025-06-02
domain cyclophilit.com IOC associated with Mirage 2025-06-02
domain cyprus-villas.org IOC associated with Mirage 2025-06-02
domain delldrivers.in IOC associated with Mirage 2025-06-02
domain dmsz.org IOC associated with Mirage 2025-06-02
domain dnsapp.info IOC associated with Mirage 2025-06-02
domain flygram.org IOC associated with Mirage 2025-06-02
domain gandeste.net IOC associated with Mirage 2025-06-02
domain geordie.land IOC associated with Mirage 2025-06-02
domain goodtobeloved.com IOC associated with Mirage 2025-06-02
domain gsenergyspeedtest.com IOC associated with Mirage 2025-06-02
domain gupdate.us IOC associated with Mirage 2025-06-02
domain hpupdate.net IOC associated with Mirage 2025-06-02
domain installcb.online IOC associated with Mirage 2025-06-02
domain kamikirim.my.id IOC associated with Mirage 2025-06-02
hostname kdr.zarkada.ru IOC associated with Mirage 2025-06-02
hostname ksbyz.jelikob.ru IOC associated with Mirage 2025-06-02
hostname log.autocount.org IOC associated with Mirage 2025-06-02
hostname mail.indiarailways.net IOC associated with Mirage 2025-06-02
hostname mail.pmumail.com IOC associated with Mirage 2025-06-02
domain mfaantivirus.xyz IOC associated with Mirage 2025-06-02
hostname micakiz.wikaba.org IOC associated with Mirage 2025-06-02
domain moneybac.ru IOC associated with Mirage 2025-06-02
domain mssync.one IOC associated with Mirage 2025-06-02
domain msupdate.top IOC associated with Mirage 2025-06-02
hostname news.memozilla.org IOC associated with Mirage 2025-06-02
domain newsinlevel.cc IOC associated with Mirage 2025-06-02
domain perusmartcity.com IOC associated with Mirage 2025-06-02
domain pfs1010.com IOC associated with Mirage 2025-06-02
domain pfs1010.xyz IOC associated with Mirage 2025-06-02
hostname proxy.oracleapps.org IOC associated with Mirage 2025-06-02
hostname proxy1.signalplus.org IOC associated with Mirage 2025-06-02
hostname proxy2.signalplus.org IOC associated with Mirage 2025-06-02
hostname proxy3.signalplus.org IOC associated with Mirage 2025-06-02
hostname proxy4.signalplus.org IOC associated with Mirage 2025-06-02
hostname proxy5.signalplus.org IOC associated with Mirage 2025-06-02
hostname proxy6.signalplus.org IOC associated with Mirage 2025-06-02
domain ridingduck.com IOC associated with Mirage 2025-06-02
hostname rmxlqabmvfnw4wp4.onion.gq IOC associated with Mirage 2025-06-02
hostname run.linodepower.com IOC associated with Mirage 2025-06-02
domain sanchaar.net IOC associated with Mirage 2025-06-02
hostname scm.oracleapps.org IOC associated with Mirage 2025-06-02
domain sherence.ru IOC associated with Mirage 2025-06-02
domain signalplus.org IOC associated with Mirage 2025-06-02
hostname singa.linodepower.com IOC associated with Mirage 2025-06-02
hostname test1.zhangliyong.cn IOC associated with Mirage 2025-06-02
domain thehollow.co IOC associated with Mirage 2025-06-02
domain thelastxmas.com IOC associated with Mirage 2025-06-02
hostname update.adboeonline.net IOC associated with Mirage 2025-06-02
hostname update.delldrivers.in IOC associated with Mirage 2025-06-02
domain upmirror.top IOC associated with Mirage 2025-06-02
hostname ve0.popmonster.ru IOC associated with Mirage 2025-06-02
domain verisims.com IOC associated with Mirage 2025-06-02
hostname video.memozilla.org IOC associated with Mirage 2025-06-02
domain wwindows.data IOC associated with Mirage 2025-06-02
hostname www.atomicmatryoshka.com IOC associated with Mirage 2025-06-02
hostname www.baddadsclub.com IOC associated with Mirage 2025-06-02
hostname www.birdsvpn.com IOC associated with Mirage 2025-06-02
hostname www.brunomassage.com IOC associated with Mirage 2025-06-02
hostname www.ciphertechsolutions.com IOC associated with Mirage 2025-06-02
hostname www.delhiopera.com IOC associated with Mirage 2025-06-02
hostname www.delldrivers.in IOC associated with Mirage 2025-06-02
hostname www.flygram.org IOC associated with Mirage 2025-06-02
hostname www.geordie.land IOC associated with Mirage 2025-06-02
hostname www.goodtobeloved.com IOC associated with Mirage 2025-06-02
hostname www.hpupdate.net IOC associated with Mirage 2025-06-02
hostname www.latavernaalmonte.com IOC associated with Mirage 2025-06-02
hostname www.numupdate.com IOC associated with Mirage 2025-06-02
hostname www.pmshyptest.com IOC associated with Mirage 2025-06-02
hostname www.pubsectors.com IOC associated with Mirage 2025-06-02
hostname www.signalplus.org IOC associated with Mirage 2025-06-02
hostname www.thelastxmas.com IOC associated with Mirage 2025-06-02
hostname www.zitoart.com IOC associated with Mirage 2025-06-02
hostname xre.popmonster.ru IOC associated with Mirage 2025-06-02
domain yusufwelding.com IOC associated with Mirage 2025-06-02
domain zipcodeterm.com IOC associated with Mirage 2025-06-02