Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
ToolAsyncRAT | AsyncRAT can enumerate the NetBIOS name on targeted machines. |
| T1036.008 Masquerade File Type |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files. |
| T1047 Windows Management Instrumentation |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT. |
| T1059.001 PowerShell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files. |
| T1059.003 Windows Command Shell |
ToolAsyncRAT | AsyncRAT can be deployed via batch script. |
| T1059.003 Windows Command Shell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host. |
| T1059.005 Visual Basic |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution. |
| T1070.004 File Deletion |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts. |
| T1071.001 Web Protocols |
MalwareUPPERCUT | UPPERCUT has used HTTP for C2, including sending error codes in cookie headers. |
| T1090.003 Multi-hop Proxy |
ToolAsyncRAT | |
| T1105 Ingress Tool Transfer |
ToolAsyncRAT | AsyncRAT has the ability to download files including over SFTP. |
| T1113 Screen Capture |
MalwareUPPERCUT | UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server. |
| T1124 System Time Discovery |
ToolAsyncRAT | AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration. |
| T1127.001 MSBuild |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool. |
| T1137.001 Office Template Macros |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT. |
| T1204.001 Malicious Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive. |
| T1204.002 Malicious File |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments. |
| T1217 Browser Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information. |
| T1219 Remote Access Tools |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY. |
| T1219.001 IDE Tunneling |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace abused Visual Studio Code (VS Code) remote tunnels to gain access and execute code on compromised machines. |
| T1553.002 Code Signing |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT. |
| T1566.001 Spearphishing Attachment |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments. |
| T1568.002 Domain Generation Algorithms |
ToolAsyncRAT | AsyncRAT use a DGA to generate a C2 domains. |
| T1574.001 DLL |
MalwareUPPERCUT | UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation. |
| T1585.002 Email Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing. |
| T1585.003 Cloud Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace established OneDrive accounts to host malicious payloads. |
| T1587.001 Malware |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools. |
| T1588.002 Tool |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus. |
| T1608.005 Link Target |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive. |
| T1685.005 Clear Windows Event Logs |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.