LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0060: Operation AkaiRyū

Operation AkaiRyū (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central Europe. Operation AkaiRyū notably included the first reported targeting of a European entity by MirrorFace, as well as their use of UPPERCUT, which was thought to be exclusive to menuPass.CitationESET MirrorFace 2025CitationTrend Micro Earth Kasha Anel NOV 2024

EnterpriseC0060CampaignObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Operation AkaiRyū matters because it shows a spearphishing-led espionage campaign can combine user-driven initial execution, Windows administration features, discovery activity, remote access tooling, and backdoor/loader malware in one intrusion pattern. For leaders, the practical question is not whether this exact campaign is present, but whether the organization can prove it would see and contain similar phishing-to-post-compromise behavior, especially where Japanese, Central European, diplomatic, academic, manufacturing, financial, defense, media, or other sensitive relationships are business-relevant.

Executive priority

Prioritize validation of email security, endpoint visibility, identity monitoring, and incident response readiness around spearphishing and follow-on execution. The ATT&CK record attributes the campaign to MirrorFace and describes targeting in Japan and Central Europe between June and September 2024, including use of UPPERCUT and other tooling. Executives should ask whether SOC and IR teams can connect a suspicious link or file to later PowerShell, command shell, WMI, MSBuild, Office macro persistence, Kerberos-related tooling, discovery commands, proxy/tunneling behavior, and remote access activity. This is useful for business continuity, audit evidence, and risk decisions because the weak point is often not one control, but gaps between email, endpoint, identity, and network telemetry.

Technical view

ATT&CK does not provide campaign-specific detection text or campaign platforms, so defenders should build validation from the related techniques and software. Focus on spearphishing follow-on behavior involving malicious links and files, Office template macros, PowerShell, Windows Command Shell, WMI, MSBuild, file deletion, system/network/file/browser discovery, remote access tools, and FRP-like proxying. The related software set includes Windows-associated malware and tools such as UPPERCUT, AsyncRAT, HiddenFace, ROAMINGHOUSE, ANELLDR, and Rubeus, plus cross-platform utilities such as Arp and FRP. Detection engineering should test whether alerts preserve the chain of evidence from initial user action through execution, persistence, discovery, credential/identity-relevant activity, command and control, and cleanup.

Likely telemetry

  • Email security logs for spearphishing links, attachments, sender metadata, URL clicks, and delivered file details
  • Endpoint process creation telemetry for PowerShell, cmd.exe, WMI activity, MSBuild.exe, Office-spawned child processes, and unusual script execution
  • Office and macro-related telemetry, including template modification or macro execution where available
  • File system events for suspicious drops, masqueraded file types, loader/backdoor artifacts, and file deletion after execution
  • Windows event logs and EDR telemetry for remote execution, WMI, command-line arguments, and parent-child process relationships

Detection direction

  • Validate correlation across email, endpoint, identity, and network events; isolated detections may miss the campaign-style sequence.
  • Tune for suspicious Office-to-script or Office-to-system-utility process chains, while accounting for legitimate administrative and developer use of PowerShell, WMI, cmd.exe, and MSBuild.
  • Review detections for masqueraded file types by comparing extension, icon, content, and file header where telemetry supports it.
  • Hunt for discovery clusters after a suspicious user action: system information, network configuration, file and directory enumeration, and browser information discovery.
  • Monitor remote access and proxy tools for abnormal use, especially where FRP-like tunneling or nonstandard remote administration appears on endpoints or servers.

Mitigation priorities

  • Start with phishing resilience: strengthen email filtering, attachment/link controls, user reporting workflows, and rapid triage of clicked links or opened files.
  • Harden execution paths commonly abused after phishing, including Office macro/template controls, script execution policy, and monitoring of trusted utilities such as WMI and MSBuild.
  • Apply least privilege and administrative separation so user-driven compromise has limited ability to execute tools, discover sensitive resources, or persist.
  • Improve endpoint detection and response coverage on Windows systems where the related tools and techniques are most represented, while noting the campaign object itself does not specify platforms.
  • Control and monitor legitimate remote access and proxy tooling; maintain an approved inventory and investigate unapproved tunnels or remote sessions.
Additional notes and limits

The most decision-useful aspect of this ATT&CK object is the relationship context: Operation AkaiRyū is described as a MirrorFace spearphishing campaign and is linked to a broad set of execution, persistence, discovery, stealth, command-and-control, remote access, and malware/tool relationships. UPPERCUT’s appearance is notable in the official description because it was previously thought to be exclusive to menuPass. This supports prioritizing detection around tool transfer, loaders, backdoors, trusted utility abuse, and post-phishing discovery rather than treating the campaign as only an email-security problem.

The official object has no campaign-level platforms, tactics, labels, or detection guidance. Related techniques and software provide useful defensive direction, but they do not prove those behaviors are present in any local environment. Claims about exposure, active exploitation, successful compromise, or detection coverage require organization-specific telemetry and investigation.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Operation AkaiRyū

Operation AkaiRyū (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central Europe. Operation AkaiRyū notably included the first reported targeting of a European entity by MirrorFace, as well as their use of UPPERCUT, which was thought to be exclusive to menuPass.CitationESET MirrorFace 2025CitationTrend Micro Earth Kasha Anel NOV 2024

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
02f5298496e11865...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.