When Three Threats Meet One Inbox Against Japan
ID: 1c79ee02-af30-5fb6-a507-afe4a0812dac
STIX ID: report--1c79ee02-af30-5fb6-a507-afe4a0812dac
Feed Name: Ransomware ISAC Blog
Date Published: 2026-06-25
Date Updated: 2026-08-21
Author: [email protected] (Md. Azim Uddin & Abdullah Al Mamun)
Unit Zero analysis details simultaneous Japan-focused activity by three distinct clusters — CoGUI (high-volume email phishing/PhaaS targeting credentials and cards), Smishing Triad (Lighthouse/Darcula-based SMS/iMessage smishing with aggressive anti-detection and bulk-SMS delivery), and MirrorFace/Earth Kasha (targeted, state-linked spearphishing and post-exploitation using ANEL/NOOPDOOR). The report examines convergence vs. coordination, infrastructure overlap, a possible Japanese localization-as-a-service ecosystem, provides IoCs (domains, IPs, hashes), defensive recommendations, and deployable detection rules (YARA, Suricata, Sigma).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
