Campaign, Jun 2004 to Sep 2004.View on attack.mitre.org
Operation AkaiRyū (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central Europe. Operation AkaiRyū notably included the first reported targeting of a European entity by MirrorFace, as well as their use of UPPERCUT, which was thought to be exclusive to menuPass.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments. |
| T1036.008 Masquerade File Type |
During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files. |
| T1047 Windows Management Instrumentation |
During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT. |
| T1059.001 PowerShell |
During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files. |
| T1059.003 Windows Command Shell |
During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host. |
| T1059.005 Visual Basic |
During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution. |
| T1070.004 File Deletion |
During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts. |
| T1082 System Information Discovery |
During Operation AkaiRyū, MirrorFace collected system information. |
| T1083 File and Directory Discovery |
During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments. |
| T1127.001 MSBuild |
During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool. |
| T1137.001 Office Template Macros |
During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT. |
| T1204.001 Malicious Link |
During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive. |
| T1204.002 Malicious File |
During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments. |
| T1217 Browser Information Discovery |
During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information. |
| T1219 Remote Access Tools |
During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.