Security researchers have uncovered new details about a sophisticated malware campaign conducted by MirrorFace, a China-linked threat actor, targeting a diplomatic organization in the European Union with a backdoor called ANEL.
ESET detected the attack, dubbed Operation AkaiRyū (Japanese for RedDragon), in August 2024. The campaign specifically targeted a Central European diplomatic institute using lures related to the upcoming World Expo in Osaka, Japan.
## Significant Shifts in Tactics
MirrorFace, also known as Earth Kasha and believed to be a subgroup of APT10, has been active since at least 2019. This operation marks two notable changes in their approach:
1. **Expanded targeting:** Previously focused exclusively on Japanese entities, the group has now broadened its scope to European organizations.
2. **Updated toolset:** The attackers deployed a heavily customized variant of AsyncRAT and revived the ANEL (UPPERCUT) backdoor, which had been discontinued around 2018-2019, replacing their previously favored LODEINFO malware.
“Unfortunately, we are not aware of any particular reason for MirrorFace to switch from using LODEINFO to ANEL,” ESET researcher Dominik Breitenbacher told The Hacker News. “However, we didn’t observe LODEINFO being used throughout the whole 2024.”
## Advanced Attack Techniques
The operation employs several sophisticated methods:
– Spear-phishing emails with malicious documents or links
– DLL side-loading to deploy the ANELLDR loader, which then decrypts and loads ANEL
– A modular backdoor called HiddenFace (NOOPDOOR) exclusive to MirrorFace
– Visual Studio Code Remote Tunnels for stealthy access to compromised systems
ESET noted that Operation AkaiRyū overlaps with “Campaign C” documented by Japan’s National Police Agency and National Center of Incident Readiness and Strategy for Cybersecurity earlier this year.
## Enhanced Operational Security
The investigation has been complicated by MirrorFace’s improved operational security measures, including:
– Deletion of delivered tools and files
– Clearing Windows event logs
– Running malware in Windows Sandbox
These tactics have made it challenging for researchers to develop a complete understanding of the group’s activities.
