Operation AkaiRyū: Europe invited to Expo 2025 and ANEL backdoor revived
Essential information
- Published
- 18/03/2025 20:59
- Modified
- 19/03/2025 09:34
- Tags
- 2025-03-18 anel apt10 asyncrat expo 2025 facexinjector hiddenface spearphishing visual studio code windows sandbox
- Related entities
- 6 observables, 1 intrusion sets (apt), 5 malware, 3 others
Description
Chinese threat actor MirrorFace expanded its cyberespionage activities beyond Japan, targeting a Central European diplomatic institute in relation to Expo 2025. The group refreshed its tactics, introducing new tools like customized AsyncRAT and reviving the ANEL backdoor previously associated with APT10. MirrorFace employed spearphishing emails with malicious attachments or links to gain initial access. The attackers used legitimate applications to stealthily install malware, including ANEL, HiddenFace, and AsyncRAT. They also abused Visual Studio Code's remote tunnels feature for stealthy access. The campaign showcased complex execution chains and the use of Windows Sandbox to avoid detection. This operation provides evidence that MirrorFace is likely a subgroup under the APT10 umbrella.