ATT&CKCampaignsOperation AkaiRyū

Operation AkaiRyū

C0060

Campaign, Jun 2004 to Sep 2004.View on attack.mitre.org

About this campaign

Operation AkaiRyū (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central Europe. Operation AkaiRyū notably included the first reported targeting of a European entity by MirrorFace, as well as their use of UPPERCUT, which was thought to be exclusive to menuPass.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1016
System Network Configuration Discovery

During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments.

T1036.008
Masquerade File Type

During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files.

T1047
Windows Management Instrumentation

During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT.

T1059.001
PowerShell

During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files.

T1059.003
Windows Command Shell

During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host.

T1059.005
Visual Basic

During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution.

T1070.004
File Deletion

During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts.

T1082
System Information Discovery

During Operation AkaiRyū, MirrorFace collected system information.

T1083
File and Directory Discovery

During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments.

T1127.001
MSBuild

During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool.

T1137.001
Office Template Macros

During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT.

T1204.001
Malicious Link

During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive.

T1204.002
Malicious File

During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments.

T1217
Browser Information Discovery

During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information.

T1219
Remote Access Tools

During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY.

View all 26 procedure examples

Attributed groups1

Software8

References2

  1. ESET MirrorFace 2025 Open source
    Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.
  2. Trend Micro Earth Kasha Anel NOV 2024 Open source
    Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.