Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Yes. ESET reported that MirrorFace targeted a Central European diplomatic institute in an operation linked to Expo 2025 in Osaka. ESET described it as the first—and, to its knowledge at the time, the only—instance of the group targeting an entity in Europe. The activity was discovered in 2024 and publicly detailed on March 18, 2025.
Who is MirrorFace?
MirrorFace is a PRC-aligned espionage actor tracked by MITRE ATT&CK as G1054. MITRE says the group has been active since at least 2019, initially focusing on Japanese organizations across media, defense, diplomacy, finance, manufacturing and academia. Its listed aliases include Earth Kasha; MITRE assesses that it is likely a subgroup under the menuPass umbrella, based on overlaps in targeting, tools and infrastructure.
Attribution is an analyst assessment, not a public legal finding. ESET’s analysis of the European activity highlighted MirrorFace’s reuse of ANEL, a backdoor previously associated with APT10, and other similarities. ESET consequently described MirrorFace as a subgroup under the APT10 umbrella. These assessments point to a relationship but should not be treated as proof that every operation attributed to one group was conducted by the other.
What was Operation AkaiRyū?
Operation AkaiRyū is ESET’s name for the activity targeting a Central European diplomatic institute. ESET discovered it during the second and third quarters of 2024 and published its findings on March 18, 2025. The institute was not publicly named in the reporting summarized here.
#1 Best Overall
ESET researcher Dominik Breitenbacher characterized the geographic significance carefully: “MirrorFace targeted a Central European diplomatic institute. To our knowledge, this is the first, and, to date, only time that MirrorFace has targeted an entity in Europe.” That is a statement about ESET’s knowledge when it reported the operation, not evidence that no other European targeting has occurred.
| When | What the reporting establishes |
|---|---|
| At least 2019 | MITRE records MirrorFace as active since at least this year, initially targeting organizations in Japan. |
| June 2024 | ESET’s activity report also describes a separate campaign targeting two employees at a Japanese research institute with a password-protected Word document and a signed McAfee executable used to load ANEL. |
| Q2–Q3 2024 | ESET discovered the activity against the Central European diplomatic institute later named Operation AkaiRyū. |
| March 18, 2025 | ESET publicly disclosed the European operation and its technical findings. |
The June 2024 activity in Japan is useful context for MirrorFace’s broader toolset, but it is distinct from the European victim and should not be conflated with the AkaiRyū attack chain.
How did the Expo 2025 phishing campaign work?
The operators reportedly made the message feel credible by referring to an earlier, legitimate interaction between the institute and a Japanese NGO. They then used Expo 2025 in Osaka as the topical lure. The combination matters: a real event can make a message look plausible, while a reference to prior correspondence can make an unexpected attachment or download seem routine.
- Use a tailored pretext. The spearphishing message referred to the institute’s previous legitimate contact with the Japanese NGO and raised Expo 2025.
- Direct the recipient to cloud-hosted content. ESET’s activity report says the email linked to a ZIP file hosted on OneDrive called The EXPO Exhibition in Japan in 2025.zip.
- Disguise the payload as a document. The ZIP contained a single Windows shortcut file named The EXPO Exhibition in Japan in 2025.docx.lnk. Although its name ended in .docx.lnk, it was an LNK shortcut, not an ordinary Word document.
- Run the malware through a layered execution chain. ESET observed a heavily customized AsyncRAT variant running inside Windows Sandbox, as well as ANEL being launched through abuse of signed applications developed by McAfee and JustSystems.
The published account does not establish that every recipient opened the file, or provide a victim count for the European operation. It also does not establish how the attackers exported data or whether data was exfiltrated. Claims that this operation definitely stole classified or personal data would go beyond what ESET reported.
Recommended Free Tools
Rank #3
What malware and tools does MirrorFace use?
ANEL, also known as UPPERCUT
ANEL is a backdoor that ESET observed in the AkaiRyū activity; it is also known as UPPERCUT and had previously been associated with APT10. ESET describes its capabilities as basic file manipulation, payload execution and screenshots. Its reuse informed ESET’s assessment of MirrorFace’s relationship to APT10.
A customized AsyncRAT variant
ESET reported a heavily customized variant of AsyncRAT in the European operation and observed it executing inside Windows Sandbox. The reporting establishes this as part of a complex chain; it does not mean that ordinary use of Windows Sandbox is itself evidence of an intrusion.
Rank #4
Signed applications used in execution
ESET observed the attackers abusing signed McAfee-developed and JustSystems-developed applications to run ANEL. A valid signature alone does not make a file or its behavior benign: the relevant question is whether the application’s execution and surrounding activity are expected in that environment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should defenders watch for?
The operation shows why defenses should account for the message context and execution behavior, not just a lure’s subject line or the presence of a familiar software signature.
Quick Recap
Best Value
- Check the context of event-themed messages. Treat unexpected Expo or other event material as potentially malicious even when the event is genuine, especially if a message invokes prior correspondence or a trusted organization.
- Inspect cloud-hosted archives and shortcuts. Review OneDrive links that lead to ZIP files, and investigate document-like filenames ending in .docx.lnk. A shortcut is executable behavior, not a document.
- Investigate unusual process activity. Look for unexpected use of Windows Sandbox and signed security or productivity applications acting as proxy executors, and assess the parent process, command line and resulting behavior rather than relying on the signature alone.
- Use consistent threat labels. Incident notes and detections can map the activity to MITRE ATT&CK group G1054 and its listed aliases, including MirrorFace and Earth Kasha, while recording the attribution confidence separately.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

