ATT&CKReferencesESET MirrorFace 2025

ESET MirrorFace 2025

Dominik Breitenbacher. (2025, March 18). Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor. Retrieved May 22, 2025.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns1

Procedure examples30

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
ToolAsyncRAT

AsyncRAT can enumerate the NetBIOS name on targeted machines.

T1036.008
Masquerade File Type
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files.

T1047
Windows Management Instrumentation
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT.

T1059.001
PowerShell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files.

T1059.003
Windows Command Shell
ToolAsyncRAT

AsyncRAT can be deployed via batch script.

T1059.003
Windows Command Shell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used `cmd.exe` to run PowerShell commands to drop additional files on the compromised host.

T1059.005
Visual Basic
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Word templates containing VBA code for malware execution.

T1070.004
File Deletion
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deleted delivered tools and files from compromised hosts.

T1071.001
Web Protocols
MalwareUPPERCUT

UPPERCUT has used HTTP for C2, including sending error codes in cookie headers.

T1090.003
Multi-hop Proxy
ToolAsyncRAT

AsyncRAT can proxy C2 through a Tor client.

T1105
Ingress Tool Transfer
ToolAsyncRAT

AsyncRAT has the ability to download files including over SFTP.

T1113
Screen Capture
MalwareUPPERCUT

UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server.

T1124
System Time Discovery
ToolAsyncRAT

AsyncRAT can check whether the current system hour and day of the week are within operating hours defined it its configuration.

T1127.001
MSBuild
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used MSBuild to compile and execute its FaceXInjector injection tool.

T1137.001
Office Template Macros
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace loaded malicious Word templates containing VBA code leading to installation of UPPERCUT.

T1204.001
Malicious Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive.

T1204.002
Malicious File
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured victims into executing malicious payloads by opening email attachments.

T1217
Browser Information Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information.

T1219
Remote Access Tools
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY.

T1219.001
IDE Tunneling
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace abused Visual Studio Code (VS Code) remote tunnels to gain access and execute code on compromised machines.

T1553.002
Code Signing
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace abused a signed McAfee executable to load UPPERCUT.

T1566.001
Spearphishing Attachment
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments.

T1568.002
Domain Generation Algorithms
ToolAsyncRAT

AsyncRAT use a DGA to generate a C2 domains.

T1574.001
DLL
MalwareUPPERCUT

UPPERCUT has been sideloaded through a legitimately signed application from the JustSystems Corporation.

T1585.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing.

T1585.003
Cloud Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace established OneDrive accounts to host malicious payloads.

T1587.001
Malware
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used custom malware, as well as customized variants of publicly available tools.

T1588.002
Tool
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace deployed multiple publicly available tools including PuTTY, FRP, and Rubeus.

T1608.005
Link Target
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive.

T1685.005
Clear Windows Event Logs
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace cleared Windows event logs post compromise.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.