Earth Kasha Refines Spear-Phishing Tactics in Espionage Campaign Targeting Taiwan and Japan
ID: 5368e335-c58d-53e9-9c8d-cc6cbab247de
STIX ID: report--5368e335-c58d-53e9-9c8d-cc6cbab247de
Feed Name: securityonline.info
Trend Micro reports a March 2025 cyber-espionage campaign by APT group Earth Kasha targeting Taiwanese and Japanese government and public institutions; attackers used spear-phishing with macro-enabled Excel lures (ROAMINGMOUSE) to deploy a chain including ANELLDR and the ANEL backdoor (now supporting in-memory BOF execution) and, for high-value targets, the NOOPDOOR backdoor with DoH-based C2, plus persistence techniques (SharpHide), indicating a significant escalation in TTPs and geopolitical targeting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
