Hiroaki, H. (2024, November 26). Guess Who’s Back - The Return of ANEL in the Recent Earth Kasha Spear-phishing Campaign in 2024. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareUPPERCUT | UPPERCUT can upload files to the C2 from infected machines. |
| T1016 System Network Configuration Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used Arp and `dir` for discovery in compromised environments. |
| T1027 Obfuscated Files or Information |
MalwareANELLDR | ANELLDR code implements anti-analysis techniques including control flow flattening and Mixed Boolean Arithmetic (MBA). |
| T1027.013 Encrypted/Encoded File |
MalwareROAMINGHOUSE | ROAMINGHOUSE can embed a ZIP file containing UPPERCUT components into three base64 encoded parts. |
| T1027.013 Encrypted/Encoded File |
MalwareANELLDR | ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data. |
| T1027.016 Junk Code Insertion |
MalwareANELLDR | ANELLDR can use junk code for payload obfuscation. |
| T1036.008 Masquerade File Type |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace disguised LNK and SFX (self-extracting) files as Word documents to lure victims into opening malicious files. |
| T1047 Windows Management Instrumentation |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading. |
| T1059.001 PowerShell |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used PowerShell in execution chains to drop additional files such as embedded CAB files. |
| T1071.001 Web Protocols |
MalwareUPPERCUT | UPPERCUT has used HTTP for C2, including sending error codes in cookie headers. |
| T1082 System Information Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the system’s hostname and OS version. |
| T1082 System Information Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace collected system information. |
| T1083 File and Directory Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments. |
| T1083 File and Directory Discovery |
MalwareANELLDR | ANELLDR can enumerate files in the current directory to search for encrypted payload files. |
| T1105 Ingress Tool Transfer |
MalwareUPPERCUT | UPPERCUT can download and upload files to and from the victim’s machine. |
| T1106 Native API |
MalwareANELLDR | ANELLDR can use the `ZwSetInformationThread` to enable debugger evasion. |
| T1113 Screen Capture |
MalwareUPPERCUT | UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server. |
| T1132.001 Standard Encoding |
MalwareUPPERCUT | UPPERCUT can base64 encode C2 communications. |
| T1137.001 Office Template Macros |
MalwareROAMINGHOUSE | ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareANELLDR | ANELLDR can decrypt encrypted payload data using AES-256-CBC and subsequently execute the payload in memory. |
| T1204.001 Malicious Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace lured users into executing malicious payloads with links to resources hosted on OneDrive. |
| T1204.002 Malicious File |
MalwareROAMINGHOUSE | During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE. |
| T1497.002 User Activity Based Checks |
MalwareROAMINGHOUSE | ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity. |
| T1548.002 Bypass User Account Control |
MalwareUPPERCUT | UPPERCUT contains functionality to bypass UAC. |
| T1566.001 Spearphishing Attachment |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace distributed crafted spearphishing emails containing malicious attachments. |
| T1566.002 Spearphishing Link |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace sent spearphishing emails with malicious OneDrive links. |
| T1573.001 Symmetric Cryptography |
MalwareUPPERCUT | Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication. |
| T1574.001 DLL |
MalwareANELLDR | ANELLDR can use DLL sideloading from a legitimate application to initiate execution. |
| T1574.001 DLL |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution. |
| T1585.002 Email Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used free email providers such as Gmail for spearphishing. |
| T1586.002 Email Accounts |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used compromised accounts to send spearphishing emails. |
| T1608.005 Link Target |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used links to direct victims to malicious files hosted on OneDrive. |
| T1622 Debugger Evasion |
MalwareANELLDR | ANELLDR can call `ZwSetInformationThread` with the second argument set to `ThreadHideFromDebugger (0x11)` to evade being debugged. |
| T1678 Delay Execution |
MalwareUPPERCUT | UPPERCUT can use a sleep function to delay execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.