In the 2024 activities analyzed in this blogpost, MirrorFace started using APT10’s former signature backdoor, ANEL, in its operations as well. Compromise chain observed in June 2024Case 2: Central European diplomatic instituteOn August 26th, 2024, MirrorFace targeted a Central European diplomatic institute. In 2024, MirrorFace started using ANEL as its first-line backdoor. ANELLDRANELLDR is a loader exclusively used to decrypt the ANEL backdoor and run it in memory. Malware and tools deployed by MirrorFace throughout the attackTools Notes Machine A Machine B ANEL APT10’s backdoor that MirrorFace uses as a first-line backdoor.