MirrorFace’s Evolving Cyberespionage Tactics: A Deep Dive into Operation AkaiRyū

Listen to this Post

A recent cyberespionage campaign linked to the China-aligned threat actor MirrorFace has showcased a significant evolution in its attack methods. The group, known for its cyber operations primarily targeting Japan, has expanded its focus, setting its sights on a Central European diplomatic institute for the first time. This shift indicates an escalation in MirrorFace’s reach and ambitions.

One of the most alarming developments in this campaign, dubbed Operation AkaiRyū, is the use of a highly customized version of AsyncRAT malware. This allows the attackers to evade detection by running malware inside Windows Sandbox, making traditional security controls ineffective. In addition, MirrorFace has revived old tools like ANEL, a backdoor associated with APT10, and leveraged Visual Studio Code’s remote tunnels to establish stealthy access.

This article explores the evasion techniques, integration of multiple attack tools, and the implications of MirrorFace’s expanding cyberespionage operations.

MirrorFace’s New Evasion Techniques

The use of Windows Sandbox is a key innovation in this latest attack. MirrorFace deploys a complex execution chain using legitimate software such as 7-Zip and PowerShell to install and execute AsyncRAT in a virtualized environment.

This technique is particularly sophisticated because:

  • Windows Sandbox needs to be manually enabled, reducing suspicion during execution.
  • The system requires a reboot, making it harder to track the infection in real time.
  • The malware operates inside an isolated environment, evading antivirus and endpoint detection tools.

The customized AsyncRAT variant also introduces:

– Sample tagging for better malware tracking.

– Tor-based communication for increased anonymity.

  • Domain Generation Algorithm (DGA), which allows malware to create unique domains for command and control (C&C) communication.

Integration with Other Attack Tools

MirrorFace’s multi-layered attack strategy involves not just AsyncRAT but also:

  1. ANEL Backdoor – An older malware linked to APT10, revived to act as the initial foothold in the attack chain.
  2. Visual Studio Code Remote Tunnels – Used to execute arbitrary code remotely on compromised machines.
  3. HiddenFace Backdoor – MirrorFace’s custom malware for persistent access and further exploitation.

By using multiple tools, MirrorFace ensures that even if one method fails, the attack can continue through other channels.

Post-Compromise Tactics & Intelligence Gathering

An investigation by ESET researchers into the affected diplomatic institute revealed that MirrorFace:

  • Tailored its attacks based on the environment—on some machines, it stole personal data, while on others, it sought deeper network access.
  • Used PuTTY, VS Code, and HiddenFace across multiple systems to maintain control and exfiltrate information.
  • Deleted logs and tools after execution, making incident analysis and attribution difficult.

This high level of operational security demonstrates MirrorFace’s growing expertise in stealthy, long-term espionage operations.

What Undercode Say:

The evolution of MirrorFace’s techniques in Operation AkaiRyū raises several critical points about the state of modern cyber warfare and nation-state threats.

1. The Strategic Use of Windows Sandbox

This is one of the first major examples of a nation-state APT group actively using Windows Sandbox as a security evasion method. Why is this important?

  • Traditional security tools struggle to monitor sandboxed environments.
  • Malware analysts cannot easily extract payloads running in an isolated system.
  • It blurs the lines between legitimate and malicious activities, making detection significantly harder.

2. The Resurgence of Older APT10 Tools

The revival of ANEL backdoor suggests a tactical shift:

  • MirrorFace might be using APT10’s old infrastructure to confuse attribution efforts.
  • Older tools often receive less scrutiny from modern security solutions, making them effective for niche operations.
  • It reinforces theories that MirrorFace is an APT10 subgroup, though the exact relationship remains unclear.

3. The Power of Multi-Layered Attacks

MirrorFace’s use of AsyncRAT, ANEL, and VS Code Tunnels highlights the growing trend of layered attack strategies.

  • This ensures multiple points of entry and persistence mechanisms.
  • Even if one tool is detected, others can maintain access and keep the attack alive.
  • Such complexity demands equally advanced defense strategies, which many organizations still lack.

4. The Expansion Beyond Japan

Targeting a Central European diplomatic institute marks a geopolitical shift in MirrorFace’s operations.

– Why move beyond Japan now?

– Possible geopolitical interests in European diplomacy.

– Testing new attack methods on non-traditional targets.

– Expanding the scope of intelligence collection.

– Implications for global cybersecurity:

  • More organizations, beyond Japan, must now prepare for MirrorFace attacks.
  • Cyber defense collaboration between regions is becoming crucial.

5. The Importance of Proactive Cyber Defense

As attackers become more sophisticated, organizations must:

  • Implement behavior-based detection to catch advanced evasion techniques.

– Strengthen endpoint monitoring for unusual activities.

  • Conduct regular threat intelligence updates to stay ahead of emerging TTPs.

MirrorFace’s success in this campaign proves that outdated security postures are no longer enough. Organizations need to continuously adapt and improve their cybersecurity defenses to counter advanced threats.

Fact Checker Results

  1. MirrorFace is linked to APT10, but direct confirmation is still debated among researchers.
  2. Operation AkaiRyū is the first known instance of MirrorFace targeting a Central European entity, showing its expanding reach.
  3. The use of Windows Sandbox for malware execution is an advanced evasion technique, making detection significantly harder for traditional security solutions.

References:

Reported By: https://cyberpress.org/mirrorface-hackers-adapt-asyncrat/
Extra Source Hub:
https://www.linkedin.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image