ATT&CKReferencesTrend Micro Earth Kasha Anel NOV 2024

Trend Micro Earth Kasha Anel NOV 2024

Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples34

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareUPPERCUT

UPPERCUT can upload files to the C2 from infected machines.

T1016
System Network Configuration Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments.

T1027
Obfuscated Files or Information
MalwareANELLDR

ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA).

T1027.013
Encrypted/Encoded File
MalwareROAMINGHOUSE

ROAMINGHOUSE can embed a ZIP file containing UPPERCUT components into three base64 encoded parts.

T1027.013
Encrypted/Encoded File
MalwareANELLDR

ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data.

T1027.016
Junk Code Insertion
MalwareANELLDR

ANELLDR can use junk code for payload obfuscation.

T1036.008
Masquerade File Type
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files.

T1047
Windows Management Instrumentation
MalwareROAMINGHOUSE

ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading.

T1059.001
PowerShell
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files.

T1071.001
Web Protocols
MalwareUPPERCUT

UPPERCUT has used HTTP for C2, including sending error codes in cookie headers.

T1082
System Information Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the system’s hostname and OS version.

T1082
System Information Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace collected system information.

T1083
File and Directory Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments.

T1083
File and Directory Discovery
MalwareANELLDR

ANELLDR can enumerate files in the current directory to search for encrypted payload files.

T1105
Ingress Tool Transfer
MalwareUPPERCUT

UPPERCUT can download and upload files to and from the victim’s machine.

T1106
Native API
MalwareANELLDR

ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion.

T1113
Screen Capture
MalwareUPPERCUT

UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server.

T1132.001
Standard Encoding
MalwareUPPERCUT

UPPERCUT can base64 encode C2 communications.

T1137.001
Office Template Macros
MalwareROAMINGHOUSE

ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro.

T1140
Deobfuscate/Decode Files or Information
MalwareANELLDR

ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory.

T1204.001
Malicious Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive.

T1204.002
Malicious File
MalwareROAMINGHOUSE

During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE.

T1497.002
User Activity Based Checks
MalwareROAMINGHOUSE

ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity.

T1548.002
Bypass User Account Control
MalwareUPPERCUT

UPPERCUT contains functionality to bypass UAC.

T1566.001
Spearphishing Attachment
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments.

T1566.002
Spearphishing Link
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links.

T1573.001
Symmetric Cryptography
MalwareUPPERCUT

Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication.

T1574.001
DLL
MalwareANELLDR

ANELLDR can use DLL sideloading from a legitimate application to initiate execution.

T1574.001
DLL
MalwareROAMINGHOUSE

ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution.

T1585.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing.

T1586.002
Email Accounts
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails.

T1608.005
Link Target
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive.

T1622
Debugger Evasion
MalwareANELLDR

ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged.

T1678
Delay Execution
MalwareUPPERCUT

UPPERCUT can use a sleep function to delay execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.