← Back to all campaigns
ActiveMITRE ATT&CK

Operation AkaiRyū

Operation AkaiRyū (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central Europe. Operation AkaiRyū notably included the first reported targeting of a European entity by MirrorFace, as well as their use of UPPERCUT, which was thought to be exclusive to menuPass.

First observedJun 1, 2004
Last observedSep 1, 2004
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

MirrorFace

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace has been active si...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

MirrorFace attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

Operation AkaiRyū last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

Operation AkaiRyū first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Related vulnerabilities 0

No linked CVEs are available.

ATT&CK techniques 43

Malware and tools 16

  • Cobalt StrikeMalware | MirrorFace
  • DOWNIISSAMalware | MirrorFace
  • HiddenFaceMalware | MirrorFace
  • LODEINFOMalware | MirrorFace
  • MirrorStealerMalware | MirrorFace
  • NOOPLDRMalware | MirrorFace
  • ROAMINGHOUSEMalware | MirrorFace
  • UPPERCUTMalware | MirrorFace
  • BITSAdminTool | MirrorFace
  • NetTool | MirrorFace
  • NltestTool | MirrorFace
  • PingTool | MirrorFace

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.