logo

Japanese police claim China ran five-year cyberattack campaign targeting local orgs

ID: 7af36024-6d05-5b20-a1da-1d4c7b68d0b1

STIX ID: report--7af36024-6d05-5b20-a1da-1d4c7b68d0b1

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-01-09

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Japan’s National Police Agency and cybersecurity center attributed a years-long (2019–2024) series of intrusions to a China-backed actor dubbed "MirrorFace"/"Earth Kasha" (linked to APT10), describing three attack waves that used targeted phishing, known backdoors (LODEINFO, NOOPDOOR, ANEL, LilimRAT), Cobalt Strike, tunneling and web shells, exploitation of TLS 1.0 and Fortinet/Citrix vulnerabilities, unauthorized Active Directory and Microsoft 365 access, and abuse of the Windows Sandbox to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.