216.73.216.6

Operation AkaiRyū: Europe invited to Expo 2025 and ANEL backdoor revived

· Published 18/03/2025 20:59 · Modified 19/03/2025 09:34

Export JSON

Essential information

Published
18/03/2025 20:59
Modified
19/03/2025 09:34
Tags
2025-03-18 anel apt10 asyncrat expo 2025 facexinjector hiddenface spearphishing visual studio code windows sandbox
Related entities
6 observables, 1 intrusion sets (apt), 5 malware, 3 others

Description

Chinese threat actor MirrorFace expanded its cyberespionage activities beyond Japan, targeting a Central European diplomatic institute in relation to . The group refreshed its tactics, introducing new tools like customized and reviving the backdoor previously associated with . MirrorFace employed emails with malicious attachments or links to gain initial access. The attackers used legitimate applications to stealthily install malware, including , , and . They also abused 's remote tunnels feature for stealthy access. The campaign showcased complex execution chains and the use of to avoid detection. This operation provides evidence that MirrorFace is likely a subgroup under the umbrella.

External references