logo

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

ID: e27ae4dd-86ba-5cb8-a621-0f38b3bf06ef

STIX ID: report--e27ae4dd-86ba-5cb8-a621-0f38b3bf06ef

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2025-03-18

Date Updated: 2026-05-01

...
...

ESET researchers detail Operation AkaiRyū, a 2024 MirrorFace (linked to APT10) cyber‑espionage campaign that used spearphishing to deliver ANEL and other backdoors, deployed a customized AsyncRAT inside Windows Sandbox, abused Visual Studio Code remote tunnels, and performed targeted post‑compromise data collection against a Central European diplomatic institute and Japanese entities; the report includes technical analysis, MITRE ATT&CK mappings, and comprehensive IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.