Revealing the Attack Operations Targeting Japan
ID: 97748ee9-8e8a-4262-8d8a-ddbf286be8c7
STIX ID: report--97748ee9-8e8a-4262-8d8a-ddbf286be8c7
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2015-11-17
Last Modified Date: 2015-11-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This JPCERT/CC briefing analyzes two long-running targeted attack operations against Japanese organizations (Operation A and Operation B), detailing initial access and lateral-movement techniques, exploited CVEs (e.g., MS14-068/MS14-058, multiple IE flaws), multiple custom malware families (Emdivi t17/t19/t20, Preshin, Derusbi, Hikit, PlugX, BeginX, GStatus, McRAT), spreading methods (watering-hole/drive-by, WPAD, update/domain hijacking, password lists, SYSVOL abuse), evidence of credential theft and domain compromise, IoCs and detection utilities (emdivi_string_decryptor.py, apt17scan.py), and an observed impact across ~130 organizations handled by JPCERT/CC during Apr–Sep 2015.
