logo

Earth Kasha Refines Spear-Phishing Tactics in Espionage Campaign Targeting Taiwan and Japan

ID: 5368e335-c58d-53e9-9c8d-cc6cbab247de

STIX ID: report--5368e335-c58d-53e9-9c8d-cc6cbab247de

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-05-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Trend Micro reports a March 2025 cyber-espionage campaign by APT group Earth Kasha targeting Taiwanese and Japanese government and public institutions; attackers used spear-phishing with macro-enabled Excel lures (ROAMINGMOUSE) to deploy a chain including ANELLDR and the ANEL backdoor (now supporting in-memory BOF execution) and, for high-value targets, the NOOPDOOR backdoor with DoH-based C2, plus persistence techniques (SharpHide), indicating a significant escalation in TTPs and geopolitical targeting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.