Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024
Essential information
- Published
- 27/11/2024 18:31
- Modified
- 27/11/2024 19:02
- Tags
- 2024-11-27 anel anelldr apt10 backdoor japan noopdoor roamingmouse spear-phishing uac bypass uppercut
- Related entities
- 6 observables, 1 intrusion sets (apt), 13 techniques (mitre), 5 malware, 3 others
Description
A spear-phishing campaign targeting Japan since June 2024 has been identified, featuring the reemergence of the ANEL backdoor, previously used by APT10 until 2018. The campaign, attributed to Earth Kasha, targets individuals in political organizations, research institutions, and international relations-related entities. The attack utilizes various infection methods, including macro-enabled documents and shortcut files. The malware suite includes ROAMINGMOUSE, ANELLDR, and updated versions of ANEL. Post-exploitation activities involve information gathering and, in some cases, deployment of the more advanced NOOPDOOR backdoor. This campaign marks a shift in Earth Kasha's tactics, moving from exploiting vulnerabilities in edge devices to targeting individuals through spear-phishing.