Threat Advisories:
Highlights of Our CISO Dinner
Upgrading struggling vulnerability management programs to Threat Exposure Management, with Host, CISO Al Lindseth formerly from Plains All American Pipeline and PWC - 6 minute podcast
0:00
0:00
👥 Play Count: Loading...

Operation AkaiRyū: MirrorFace Expands Cyberespionage to Europe with Revived Tools

Amber | Attack Report
Download PDF

In August 2024, a cyberespionage campaign by the China-aligned MirrorFace APT group was uncovered, marking its first known attempt to breach a European entity. Traditionally focused on Japan-linked targets, MirrorFace launched Operation AkaiRyū (Red Dragon in Japanese), unveiling a refreshed arsenal of tactics and tools. This campaign introduced a customized AsyncRAT, resurrected the ANEL backdoor, and leveraged a sophisticated execution chain to evade detection, deploying AsyncRAT inside Windows Sandbox for stealthy operations.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox