PULSE NAME
Threat Actor Profile: Mirage
WHITE fraevolquez 2025-06-17 Modified: 2025-06-17
95
IOCs
HIGH VOLUME
# Mirage - Threat Actor Profile **Report Date**: 2025-06-17 **Actor Type**: unknown ## Description Mirage is a sophisticated cyber espionage group believed to be linked to Chinas Peoples Liberation Army PLA. The groups primary focus is on intelligence gathering, targeting sectors like aerospace and defense. They employ a variety of tactics and tools, including custom malware. ## Targeted Sectors * Administración pública * Transporte aéreo * Manufactura * Investigación y tecnología espacial * Servicios públicos * ... y 10 más ## Targeted Countries * República Dominicana * India 2 * Ghana * Siria * Venezuela * ... y 61 más
Indicators of Compromise (95)
All CVE hostname domain
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2012-0158 IOC associated with Mirage 2025-06-17
CVE CVE-2015-2546 IOC associated with Mirage 2025-06-17
CVE CVE-2017-11882 IOC associated with Mirage 2025-06-17
CVE CVE-2021-31207 IOC associated with Mirage 2025-06-17
CVE CVE-2021-34473 IOC associated with Mirage 2025-06-17
CVE CVE-2021-34523 IOC associated with Mirage 2025-06-17
hostname 6b4s.popmonster.ru IOC associated with Mirage 2025-06-17
hostname 9356.popmonster.ru IOC associated with Mirage 2025-06-17
domain actuallys.com IOC associated with Mirage 2025-06-17
hostname afg.collinformations.com IOC associated with Mirage 2025-06-17
domain andspurs.com IOC associated with Mirage 2025-06-17
hostname apps.androidupdated.net IOC associated with Mirage 2025-06-17
domain asistechs.com IOC associated with Mirage 2025-06-17
hostname b.popmonster.ru IOC associated with Mirage 2025-06-17
domain baddadsclub.com IOC associated with Mirage 2025-06-17
hostname bat.androidupdated.net IOC associated with Mirage 2025-06-17
domain beltsymd.org IOC associated with Mirage 2025-06-17
domain cancelle.net IOC associated with Mirage 2025-06-17
domain cavanic9.net IOC associated with Mirage 2025-06-17
domain cognacbrown.co.uk IOC associated with Mirage 2025-06-17
domain cyclophilit.com IOC associated with Mirage 2025-06-17
domain cyprus-villas.org IOC associated with Mirage 2025-06-17
domain delldrivers.in IOC associated with Mirage 2025-06-17
domain dmsz.org IOC associated with Mirage 2025-06-17
domain dnsapp.info IOC associated with Mirage 2025-06-17
domain flygram.org IOC associated with Mirage 2025-06-17
domain gandeste.net IOC associated with Mirage 2025-06-17
domain geordie.land IOC associated with Mirage 2025-06-17
domain goodtobeloved.com IOC associated with Mirage 2025-06-17
domain gsenergyspeedtest.com IOC associated with Mirage 2025-06-17
domain gupdate.us IOC associated with Mirage 2025-06-17
domain hpupdate.net IOC associated with Mirage 2025-06-17
domain installcb.online IOC associated with Mirage 2025-06-17
domain kamikirim.my.id IOC associated with Mirage 2025-06-17
hostname kdr.zarkada.ru IOC associated with Mirage 2025-06-17
hostname ksbyz.jelikob.ru IOC associated with Mirage 2025-06-17
hostname log.autocount.org IOC associated with Mirage 2025-06-17
hostname mail.indiarailways.net IOC associated with Mirage 2025-06-17
hostname mail.pmumail.com IOC associated with Mirage 2025-06-17
domain mfaantivirus.xyz IOC associated with Mirage 2025-06-17
hostname micakiz.wikaba.org IOC associated with Mirage 2025-06-17
domain moneybac.ru IOC associated with Mirage 2025-06-17
domain mssync.one IOC associated with Mirage 2025-06-17
domain msupdate.top IOC associated with Mirage 2025-06-17
hostname news.memozilla.org IOC associated with Mirage 2025-06-17
domain newsinlevel.cc IOC associated with Mirage 2025-06-17
domain perusmartcity.com IOC associated with Mirage 2025-06-17
domain pfs1010.com IOC associated with Mirage 2025-06-17
domain pfs1010.xyz IOC associated with Mirage 2025-06-17
hostname proxy.oracleapps.org IOC associated with Mirage 2025-06-17
hostname proxy1.signalplus.org IOC associated with Mirage 2025-06-17
hostname proxy2.signalplus.org IOC associated with Mirage 2025-06-17
hostname proxy3.signalplus.org IOC associated with Mirage 2025-06-17
hostname proxy4.signalplus.org IOC associated with Mirage 2025-06-17
hostname proxy5.signalplus.org IOC associated with Mirage 2025-06-17
hostname proxy6.signalplus.org IOC associated with Mirage 2025-06-17
domain ridingduck.com IOC associated with Mirage 2025-06-17
hostname rmxlqabmvfnw4wp4.onion.gq IOC associated with Mirage 2025-06-17
hostname run.linodepower.com IOC associated with Mirage 2025-06-17
domain sanchaar.net IOC associated with Mirage 2025-06-17
hostname scm.oracleapps.org IOC associated with Mirage 2025-06-17
domain sherence.ru IOC associated with Mirage 2025-06-17
domain signalplus.org IOC associated with Mirage 2025-06-17
hostname singa.linodepower.com IOC associated with Mirage 2025-06-17
hostname test1.zhangliyong.cn IOC associated with Mirage 2025-06-17
domain thehollow.co IOC associated with Mirage 2025-06-17
domain thelastxmas.com IOC associated with Mirage 2025-06-17
hostname update.adboeonline.net IOC associated with Mirage 2025-06-17
hostname update.delldrivers.in IOC associated with Mirage 2025-06-17
domain upmirror.top IOC associated with Mirage 2025-06-17
hostname ve0.popmonster.ru IOC associated with Mirage 2025-06-17
domain verisims.com IOC associated with Mirage 2025-06-17
hostname video.memozilla.org IOC associated with Mirage 2025-06-17
domain wwindows.data IOC associated with Mirage 2025-06-17
hostname www.atomicmatryoshka.com IOC associated with Mirage 2025-06-17
hostname www.baddadsclub.com IOC associated with Mirage 2025-06-17
hostname www.birdsvpn.com IOC associated with Mirage 2025-06-17
hostname www.brunomassage.com IOC associated with Mirage 2025-06-17
hostname www.ciphertechsolutions.com IOC associated with Mirage 2025-06-17
hostname www.delhiopera.com IOC associated with Mirage 2025-06-17
hostname www.delldrivers.in IOC associated with Mirage 2025-06-17
hostname www.flygram.org IOC associated with Mirage 2025-06-17
hostname www.geordie.land IOC associated with Mirage 2025-06-17
hostname www.goodtobeloved.com IOC associated with Mirage 2025-06-17
hostname www.hpupdate.net IOC associated with Mirage 2025-06-17
hostname www.latavernaalmonte.com IOC associated with Mirage 2025-06-17
hostname www.numupdate.com IOC associated with Mirage 2025-06-17
hostname www.pmshyptest.com IOC associated with Mirage 2025-06-17
hostname www.pubsectors.com IOC associated with Mirage 2025-06-17
hostname www.signalplus.org IOC associated with Mirage 2025-06-17
hostname www.thelastxmas.com IOC associated with Mirage 2025-06-17
hostname www.zitoart.com IOC associated with Mirage 2025-06-17
hostname xre.popmonster.ru IOC associated with Mirage 2025-06-17
domain yusufwelding.com IOC associated with Mirage 2025-06-17
domain zipcodeterm.com IOC associated with Mirage 2025-06-17