Chinese APT Group Is Ransacking Japan's Secrets
ID: 5f5aa8f5-a461-55a1-84c6-f618458ca7d5
STIX ID: report--5f5aa8f5-a461-55a1-84c6-f618458ca7d5
Feed Name: Dark Reading
Date Published: 2025-01-10
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Japanese authorities warn that MirrorFace, a Chinese state-backed APT active since 2019, has targeted think tanks, government, media, healthcare, manufacturing, education, and aerospace using spear-phishing, SQL injection, and exploitation of known Fortinet and Citrix vulnerabilities (including CVE-2023-28461, CVE-2023-27997, CVE-2023-3519); the group has deployed malware such as LODEINFO and MirrorStealer to steal credentials and exfiltrate sensitive information, with observed activity continuing into 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
