None
EN
Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor
[]
WeLiveSecurity
In the 2024 activities analyzed in this blogpost, MirrorFace started using APT10’s former signature backdoor, ANEL, in its operations as well.
Compromise chain observed in June 2024Case 2: Central European diplomatic instituteOn August 26th, 2024, MirrorFace targeted a Central European diplomatic institute.
In 2024, MirrorFace started using ANEL as its first-line backdoor.
ANELLDRANELLDR is a loader exclusively used to decrypt the ANEL backdoor and run it in memory.
Malware and tools deployed by MirrorFace throughout the attackTools Notes Machine A Machine B ANEL APT10’s backdoor that MirrorFace uses as a first-line backdoor.
['machine'
'mirrorface'
'code'
'2024'
'2025'
'revives'
'europe'
'anel'
'asyncrat'
'invites'
'akairyū'
'backdoor'
'operation'
'using'
'file'
'malicious'
'expo']