Japanese police claim China ran five-year cyberattack campaign targeting local orgs
ID: 7af36024-6d05-5b20-a1da-1d4c7b68d0b1
STIX ID: report--7af36024-6d05-5b20-a1da-1d4c7b68d0b1
Feed Name: The Register (Security)
Japan’s National Police Agency and cybersecurity center attributed a years-long (2019–2024) series of intrusions to a China-backed actor dubbed "MirrorFace"/"Earth Kasha" (linked to APT10), describing three attack waves that used targeted phishing, known backdoors (LODEINFO, NOOPDOOR, ANEL, LilimRAT), Cobalt Strike, tunneling and web shells, exploitation of TLS 1.0 and Fortinet/Citrix vulnerabilities, unauthorized Active Directory and Microsoft 365 access, and abuse of the Windows Sandbox to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
