logo

When Three Threats Meet One Inbox Against Japan

ID: 1c79ee02-af30-5fb6-a507-afe4a0812dac

STIX ID: report--1c79ee02-af30-5fb6-a507-afe4a0812dac

Feed Name: Ransomware ISAC Blog

Threat Score
88/100

Date Published: 2026-06-25

Date Updated: 2026-08-21

Author: [email protected] (Md. Azim Uddin & Abdullah Al Mamun)

...
...

Unit Zero analysis details simultaneous Japan-focused activity by three distinct clusters — CoGUI (high-volume email phishing/PhaaS targeting credentials and cards), Smishing Triad (Lighthouse/Darcula-based SMS/iMessage smishing with aggressive anti-detection and bulk-SMS delivery), and MirrorFace/Earth Kasha (targeted, state-linked spearphishing and post-exploitation using ANEL/NOOPDOOR). The report examines convergence vs. coordination, infrastructure overlap, a possible Japanese localization-as-a-service ecosystem, provides IoCs (domains, IPs, hashes), defensive recommendations, and deployable detection rules (YARA, Suricata, Sigma).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.