logo

Chinese APT Group Is Ransacking Japan's Secrets

ID: 5f5aa8f5-a461-55a1-84c6-f618458ca7d5

STIX ID: report--5f5aa8f5-a461-55a1-84c6-f618458ca7d5

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-01-10

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Japanese authorities warn that MirrorFace, a Chinese state-backed APT active since 2019, has targeted think tanks, government, media, healthcare, manufacturing, education, and aerospace using spear-phishing, SQL injection, and exploitation of known Fortinet and Citrix vulnerabilities (including CVE-2023-28461, CVE-2023-27997, CVE-2023-3519); the group has deployed malware such as LODEINFO and MirrorStealer to steal credentials and exfiltrate sensitive information, with observed activity continuing into 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.