IOC Radar
TLP:WHITE7 IOCs

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

BO
Botvrij.eu OSINT Feed
Published April 3, 2025Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE45.32.116.146vu4fleh3yd4ehpfpciinn…64.176.56.26CAPABILITYAsyncRATVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise7

TypeIndicatorConfidenceScoreFirst Seen
IP45.32.116.146
anonymizationc2malware
High
68
Jun 2, 26
Domainvu4fleh3yd4ehpfpciinnwbnh4b77rdeypubhqr2dgfibjtvxpdxozid.onion
anonymizationc2malware
High
68
Jun 2, 26
IP64.176.56.26
anonymizationc2malware
High
68
Jun 2, 26
Domainu4mrhg3y6jyfw2dmm2wnocz3g3etp2xc5thzx77uelk7mrk7qtjmc6qd.onion
anonymizationc2malware
High
68
Jun 2, 26
IP152.42.202.137
malwarenetworkrat
High
68
Jun 2, 26
IP104.233.167.135
c2malwarenetwork
High
68
Jun 2, 26
IP208.85.18.4
malwarenetworkproxy
High
68
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph7 total IOCs
IPDomain
IP5Domain2Malware1REPORTOperation AkaiRyū: MirrorFAsyncRAT
scroll to zoom · drag to pan · click IOC to open