State-sponsored hackers MirrorFace have been linked to the spread of the ROAMINGMOUSE malware and the ANEL backdoor, as part of a digital espionage campaign targeting government agencies and public institutions in Japan and Taiwan.

The activity was detected by Trend Micro in March 2025 and was based on targeted spear-phishing attacks, through which an upgraded variant of the ANEL backdoor.
According to cybersecurity analyst Hara Hiroaki, the new version of ANEL incorporates a command that allows Beacon Object Files (BOF) to be executed directly in memory, making it more difficult to detect. In addition, the campaign used the SharpHide to activate a second backdoor, called NOOPDOOR.
See also: ClickFix: COLDRIVER hackers distribute LOSTKEYS malware
The focus of Chinese hackers MirrorFace on government and public agencies in both Japan and Taiwan demonstrates the group's expanding activity, as it appears to be seeking systematic information collection that serves geopolitical goals.
How exactly does the attack work?
The attack begins by sending targeted phishing emails, some of which appear to come from legitimate but compromised email. These emails contain a link to Microsoft OneDrive, from which a compressed (ZIP) file is downloaded.
Inside this file is an Excel, loaded with malicious code, as well as a macro-enabled dropper, known as ROAMINGMOUSE. ROAMINGMOUSE's role is to trigger the loading of additional malicious elements, including those related to the ANEL backdoor — a tool that MirrorFace has already been using since last year.
As researcher Hiroaki, ROAMINGMOUSE decodes the embedded ZIP file via Base64, stores it locally , and decompresses its contents. The resulting files include:
- A legitimate executable file, such as
JSLNTOOL.exe,JSTIEE.exe, orJSVWMNG.exe - JSFC.dll, also known as ANELLDR, which acts as a loader
- An encrypted ANEL payload
- MSVCR100.dll, a legitimate DLL dependency of the executable
See also: CoGUI: New phishing kit has targeted millions of users
The ultimate goal of the attack chain is to launch the legitimate executable using explorer.exe and then use it to load the malicious DLL, in this case, ANELLDR, which is responsible for decrypting and launching the ANEL backdoor.
According to the researchers, the updated ANEL has gained new capabilities, including a command that supports executing Beacon Object Files (BOFs) directly in memory. BOFs are C microprograms designed to extend the Cobalt Strike agent with new post-exploitation features.

“After installing ANEL, the attackers took screenshots using a backdoor command and examined the victim’s environment,” Trend Micro explained. “The adversary appears to investigate the victim by looking at screenshots, executing process lists, and domain information.”
Some of the incidents involved the use of SharpHide, an open source tool that facilitated the execution of an enhanced version of NOOPDOOR (also known as HiddenFace). This malware has support for DNS-over-HTTPS (DoH).
Malware protection
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New EDR bypass “Bring Your Own Installer” used in ransomware attacks
Information security training is also crucial. This means employees need to learn to recognize and avoid phishing attacks, which attackers often use to install malware.
It's also important to keep your operating system and applications up to date. These updates often include security patches that can protect your computer from the latest threats.
Also, don't forget to use firewalls and monitor network traffic to help immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.
Source: thehackernews.com
