HomeSecurityMirrorFace hackers target Japan with ROAMINGMOUSE and ANEL

MirrorFace hackers target Japan with ROAMINGMOUSE and ANEL

State-sponsored hackers MirrorFace have been linked to the spread of the ROAMINGMOUSE malware and the ANEL backdoor, as part of a digital espionage campaign targeting government agencies and public institutions in Japan and Taiwan.

hackers MirrorFace Japan ROAMINGMOUSE and ANEL

The activity was detected by Trend Micro in March 2025 and was based on targeted spear-phishing attacks, through which an upgraded variant of the ANEL backdoor.

According to cybersecurity analyst Hara Hiroaki, the new version of ANEL incorporates a command that allows Beacon Object Files (BOF) to be executed directly in memory, making it more difficult to detect. In addition, the campaign used the SharpHide to activate a second backdoor, called NOOPDOOR.

See also: ClickFix: COLDRIVER hackers distribute LOSTKEYS malware

The focus of Chinese hackers MirrorFace on government and public agencies in both Japan and Taiwan demonstrates the group's expanding activity, as it appears to be seeking systematic information collection that serves geopolitical goals.

How exactly does the attack work?

The attack begins by sending targeted phishing emails, some of which appear to come from legitimate but compromised email. These emails contain a link to Microsoft OneDrive, from which a compressed (ZIP) file is downloaded.

Inside this file is an Excel, loaded with malicious code, as well as a macro-enabled dropper, known as ROAMINGMOUSE. ROAMINGMOUSE's role is to trigger the loading of additional malicious elements, including those related to the ANEL backdoor — a tool that MirrorFace has already been using since last year.

As researcher Hiroaki, ROAMINGMOUSE decodes the embedded ZIP file via Base64, stores it locally , and decompresses its contents. The resulting files include:

  • A legitimate executable file, such as JSLNTOOL.exe, JSTIEE.exe , or JSVWMNG.exe
  • JSFC.dll, also known as ANELLDR, which acts as a loader
  • An encrypted ANEL payload
  • MSVCR100.dll, a legitimate DLL dependency of the executable

See also: CoGUI: New phishing kit has targeted millions of users

The ultimate goal of the attack chain is to launch the legitimate executable using explorer.exe and then use it to load the malicious DLL, in this case, ANELLDR, which is responsible for decrypting and launching the ANEL backdoor.

According to the researchers, the updated ANEL has gained new capabilities, including a command that supports executing Beacon Object Files (BOFs) directly in memory. BOFs are C microprograms designed to extend the Cobalt Strike agent with new post-exploitation features.

MirrorFace hackers target Japan with ROAMINGMOUSE and ANEL
MirrorFace hackers target Japan with ROAMINGMOUSE and ANEL

“After installing ANEL, the attackers took screenshots using a backdoor command and examined the victim’s environment,” Trend Micro explained. “The adversary appears to investigate the victim by looking at screenshots, executing process lists, and domain information.”

Some of the incidents involved the use of SharpHide, an open source tool that facilitated the execution of an enhanced version of NOOPDOOR (also known as HiddenFace). This malware has support for DNS-over-HTTPS (DoH).

Malware protection

Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New EDR bypass “Bring Your Own Installer” used in ransomware attacks

Information security training is also crucial. This means employees need to learn to recognize and avoid phishing attacks, which attackers often use to install malware.

It's also important to keep your operating system and applications up to date. These updates often include security patches that can protect your computer from the latest threats.

Also, don't forget to use firewalls and monitor network traffic to help immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.

Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS