logo

Revealing the Attack Operations Targeting Japan

ID: 97748ee9-8e8a-4262-8d8a-ddbf286be8c7

STIX ID: report--97748ee9-8e8a-4262-8d8a-ddbf286be8c7

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2015-11-17

Last Modified Date: 2015-11-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This JPCERT/CC briefing analyzes two long-running targeted attack operations against Japanese organizations (Operation A and Operation B), detailing initial access and lateral-movement techniques, exploited CVEs (e.g., MS14-068/MS14-058, multiple IE flaws), multiple custom malware families (Emdivi t17/t19/t20, Preshin, Derusbi, Hikit, PlugX, BeginX, GStatus, McRAT), spreading methods (watering-hole/drive-by, WPAD, update/domain hijacking, password lists, SYSVOL abuse), evidence of credential theft and domain compromise, IoCs and detection utilities (emdivi_string_decryptor.py, apt17scan.py), and an observed impact across ~130 organizations handled by JPCERT/CC during Apr–Sep 2015.