Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0060
MITRE ATT&CK Campaign · 2004–2004

Operation AkaiRyū (C0060)

ShareXLinkedInRedditHN

[Operation AkaiRyū](https://attack.mitre.org/campaigns/C0060) (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by [MirrorFace](https://attack.mitre.org/groups/G1054) between June and September 2024 against entities in Japan and Central Europe. [Operation AkaiRyū](https://attack.mitre.org/campaigns/C0060) notably included the first reported targeting of a European entity by [MirrorFace](https://attack.mitre.org/groups/G1054), as well as their use of [UPPERCUT](https://attack.mitre.org/software/S0275), which was thought to be exclusive to [menuPass](https://attack.mitre.org/groups/G0045).(Citation: ESET MirrorFace 2025)(Citation: Trend Micro Earth Kasha Anel NOV 2024)

▪Attributed groups (1)

G1054MirrorFace

▪Techniques used (26)

T1204.001Malicious LinkT1059.005Visual BasicT1588.002ToolT1082System Information DiscoveryT1585.003Cloud AccountsT1204.002Malicious FileT1587.001MalwareT1127.001MSBuildT1685.005Clear Windows Event LogsT1553.002Code SigningT1059.003Windows Command ShellT1016System Network Configuration DiscoveryT1070.004File DeletionT1219.001IDE TunnelingT1083File and Directory DiscoveryT1608.005Link TargetT1566.001Spearphishing AttachmentT1217Browser Information DiscoveryT1219Remote Access ToolsT1566.002Spearphishing LinkT1586.002Email AccountsT1047Windows Management InstrumentationT1137.001Office Template MacrosT1036.008Masquerade File TypeT1059.001PowerShellT1585.002Email Accounts

▪Software used (8)

S9026ROAMINGHOUSEmalwareS9023HiddenFacemalwareS9027ANELLDRmalwareS1087AsyncRATtoolS0099ArptoolS0275UPPERCUTmalwareS1071RubeustoolS1144FRPtool
C0060on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.