Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Mirrorface targets Japan and Taiwan with RoamingMouse and upgraded Anel malware
Celebrities

Mirrorface targets Japan and Taiwan with RoamingMouse and upgraded Anel malware

By May 8, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 8, 2025Ravi LakshmananMalware/Cyberspy

RoamingMouse and upgraded Anel malware

It has been observed that Nation-State threat actors, known as Mirrorface, are deploying malware called RoamingMouse as part of cyberspy activities directed to government and public agencies in Japan and Taiwan.

Activities detected in Trend Micro in March 2025 included the use of a spearfishing racker to provide an updated version of the backdoor called Anel.

“The ANEL file for the 2025 campaign discussed in this blog has implemented a new command to support the execution of BOFs (beacon object files) in memory,” says security researcher Hara Hiroaki. “This campaign could also utilize Sharpd to launch a second-phase backdoor Noopdoor.”

The China-lined threat actors, also known as Earthkasha, are rated as subclusters within APT10. In March 2025, ESET shed light on a campaign called Operation Akairyū in August 2024 targeting Anel (aka Uppercut) and diplomatic organisations in the European Union.

Cybersecurity

Targeting various entities in Japan and Taiwan points to a continuous expansion of footprints as hacking crews seek to carry out information theft to advance their strategic goals.

The attack begins with a spear phishing email – some of it is sent from a legal but compromised account – contains an embedded Microsoft OneDrive URL, which downloads a ZIP file.

The ZIP archive contains malware-covered Excel documents and RoamingMouse, a macro-enabled dropper codename that acts as a conduit to deliver components related to ANEL. It is worth noting that Roaming Mouse has been used by Mirrorface since last year.

“RoamingMouse uses Base64 to decode embedded ZIP files, drop zips on disk, and extend the components,” says Hiroaki. This is –

jslntool.exe, jstiie.exe, or jsvwmng.exe (legal binary) JSFC.dll (aneldr) Encrypted ANEL payload MSVCR100.dll (legal DLL dependencies for executables)

The ultimate goal of the attack chain is to launch a legitimate executable using Explorer.exe and use it to remove malicious DLLs, in this case Aneldr.

What’s noteworthy about the ANEL artifact used in the 2025 campaign is that it adds new commands with new commands to support in-memory execution of Beacon Object Files (BOFS). It compiles a C program designed to extend the Cobalt Strike Agent with new post-explosion functionality.

“After installing the ANEL file, the actor behind Earth Kasha used backdoor commands to take screenshots and examine the victim’s environment,” explained Trend Micro. “The enemy appears to be looking at screenshots, running a process list, examining domain information to investigate victims.”

Cybersecurity

It also leverages an open source tool named Sharphide to use the selected instance to launch another new backdoor version of Noopdoor (aka Hiddenface), which was previously identified as used by Hacking Group. The implant supports DNS-over-HTTPS (DOH) for that part, hiding IP address searches during command and control (C2) operations.

“Earthkasha continues to be an aggressive, highly sustained threat, and is currently targeting government and public institutions and public institutions at Taiwan and Japan in its latest campaign detected in March 2025,” Hiroaki said.

“Companies and organizations, particularly those with high value assets such as governance-related sensitive data, intellectual property, infrastructure data, and access credentials, should remain vigilant and implement proactive security measures to prevent victims of cyberattacks.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHAC welcomes the London Competition for the 9th consecutive year
Next Article Why Hims & Hers turn to the autonomous vehicle industry and find AI-savvy CTOs

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Trending Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.