Overview
Operation AkaiRyū (Japanese for “Red Dragon”; MITRE ATT&CK ID C0060) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024, per MITRE’s campaign description, against entities in Japan and Central Europe. MITRE notes this campaign included the first reported targeting of a European entity by MirrorFace, as well as the group’s first documented use of UPPERCUT — malware previously thought to be exclusive to a separate group, menuPass.
Timeline: correcting an apparent typo in MITRE’s upstream data
MITRE’s description text states the campaign ran “between June and September 2024.” We display June–September 2024 above. That is a correction, not MITRE’s raw value: the structured first_seen/last_seen fields in MITRE’s own published STIX bundle (verified directly against raw.githubusercontent.com/mitre/cti, object campaign--8a7c55ea-f363-4a03-b4c5-fa3fdb132d8f) literally read June 2004 to September 2004 — a year off from the description text on the same object.
We’re confident this is a data-entry typo in MITRE’s own source, not a real second, earlier campaign: both citations backing this entry (ESET, published March 2025; Trend Micro, published November 2024) postdate 2004 by two decades, and the object’s own x_mitre_first_seen_citation field ties the 2004-tagged date directly to those same 2024/2025 sources. There is no scenario in which sources published in 2024–2025 are reporting on events from 2004. We display the corrected year rather than MITRE’s literal field value because publishing a citation-contradicted date would be more misleading than correcting it — but we document the discrepancy here in full rather than silently editing MITRE’s data without a trace, consistent with never presenting a correction as if it were the source’s own unmodified statement.
Actors and malware involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK attributes this campaign to MirrorFace. Malware documented includes ROAMINGHOUSE, HiddenFace, ANELLDR, AsyncRAT, UPPERCUT, and Rubeus, alongside FRP and Arp.
What we don’t have
Beyond the date-field discrepancy noted above, we have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no confirmation of the specific European entity or entities targeted beyond MITRE’s general “Central Europe” description.
Frequently Asked Questions
What was Operation AkaiRyū? A cyberespionage spearphishing campaign, per MITRE ATT&CK’s description text, conducted by MirrorFace between June and September 2024 against targets in Japan and, for the first time, Central Europe.
Why does this article correct a date? MITRE’s structured first-seen/last-seen fields in its own published STIX bundle read June–September 2004, not 2024 — but every citation backing that date was published in 2024–2025, making 2004 an internal typo in MITRE’s source data. We display the citation-consistent 2024 date and document the discrepancy rather than silently reproducing an inconsistent raw value.
What made this campaign notable? Per MITRE’s description, it was MirrorFace’s first reported targeting of a European entity, and the group’s first documented use of UPPERCUT malware, previously thought exclusive to a different group (menuPass).
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0060, aggregated August 28, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.