logo

When Three Threats Meet One Inbox Against Japan

ID: 7f481957-9512-5e69-81fd-e80ca01032e2

STIX ID: report--7f481957-9512-5e69-81fd-e80ca01032e2

Feed Name: Ransomware ISAC Blog

Threat Score
88/100

Date Published: 2026-06-25

Date Updated: 2026-07-29

Author: [email protected] (Md. Azim Uddin & Abdullah Al Mamun)

...
...

This report analyzes three concurrent Japan-focused threats—CoGUI (large-scale Chinese-language phishing kit), Smishing Triad (Lighthouse/Darcula smishing franchise), and MirrorFace/Earth Kasha (APT-associated spearphishing and implants)—documenting their TTPs, infrastructure overlap, IoCs (domains, IPs, SHA256 hashes), and recommended defensive priorities (behavioral detections over short-lived IoCs). It highlights high operational scale and sophistication, the delivery advantage of iMessage in Japan, cultural disclosure risks that lengthen dwell time, and the critical open question of a shared Japanese localization-as-a-service that could multiply impact if disrupted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.