When Three Threats Meet One Inbox Against Japan
ID: 7f481957-9512-5e69-81fd-e80ca01032e2
STIX ID: report--7f481957-9512-5e69-81fd-e80ca01032e2
Feed Name: Ransomware ISAC Blog
Date Published: 2026-06-25
Date Updated: 2026-07-29
Author: [email protected] (Md. Azim Uddin & Abdullah Al Mamun)
This report analyzes three concurrent Japan-focused threats—CoGUI (large-scale Chinese-language phishing kit), Smishing Triad (Lighthouse/Darcula smishing franchise), and MirrorFace/Earth Kasha (APT-associated spearphishing and implants)—documenting their TTPs, infrastructure overlap, IoCs (domains, IPs, SHA256 hashes), and recommended defensive priorities (behavioral detections over short-lived IoCs). It highlights high operational scale and sophistication, the delivery advantage of iMessage in Japan, cultural disclosure risks that lengthen dwell time, and the critical open question of a shared Japanese localization-as-a-service that could multiply impact if disrupted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
