Bridging individuals with technology thru innovative solutions & delivery of excellence in  service.

G360-Expanded

440.973.6652

Bridging individuals with technology thru innovative solutions & delivery of excellence in  service.

Updated attack arsenal leveraged in MirrorFace attacks against Japan, Taiwan

Updated attack arsenal leveraged in MirrorFace attacks against Japan, Taiwan

May 9, 2025



Attacks with the ROAMINGHOUSE malware and an updated ANEL backdoor have been launched by Chinese hacking operation MirrorFace, also known as Earth Kasha, against Japanese and Taiwanese government agencies and public entities as part of a new cyberespionage campaign, according to The Hacker News.MirrorFace distributes spear-phishing emails with a OneDrive URL that downloads a ZIP file containing the ROAMINGHOUSE dropper, which decodes the ZIP file to deploy the legitimate executable and sideload a malicious DLL that injects the improved ANEL backdoor, a report from Trend Micro revealed. Installation of the backdoor, which has since gained a new in-memory beacon object file execution capability, then enables MirrorFace to procure screenshots and evaluate targeted environments. “Enterprises and organizations, especially those with high-value assets like sensitive data relating to governance, as well as intellectual property, infrastructure data, and access credentials, should continue to be vigilant and implement proactive security measures to prevent falling victim to cyberattacks,” said Trend Micro researcher Hara Hiroaki.



Source link

You May Also Like…

0 Comments