Multiple cyber-espionage campaigns targeted Japanese and broader Asia-Pacific organizations by combining spear-phishing, watering-hole compromises, and exploitation of both widely used and region-specific software vulnerabilities. Reporting links activity against Japanese government agencies, manufacturers, trading firms, petroleum and mobile organizations, and Taiwan government targets to groups including DragonOK, Blue Termite/Cloudy Omega, APT17, BRONZE BUTLER/Tick, and the operators behind MILE TEA. Attackers repeatedly abused Japanese software such as Sanshiro, Ichitaro, and SKYSEA Client View, while also relying on older Microsoft Office flaws such as CVE-2012-0158 and other Windows vulnerabilities to deliver malware including PlugX, Emdivi, Agtid, Wali, Datper, NodeRAT, Elirks, Micrass, and Logedrut.
Palo Alto Networks documented a 2015 DragonOK phishing operation against Japanese targets that used the biosnews[.]info command-and-control server to stage Sysget/HelloBridge, NFlog, PoisonIvy, NewCT, PlugX, and the custom FormerFirstRAT backdoor. The same threat ecosystem was later tied to a watering-hole attack on an aerospace firm website that served an Adobe Flash exploit for CVE-2015-5122 and installed the IsSpace backdoor, assessed as an evolution of NFlog. Separate tracking of MILE TEA showed a long-running campaign from at least 2011 through 2016 that used flight e-ticket lures, custom installers, and malware that fetched command-and-control addresses from public blog pages, while Trend Micro reported continued heavy exploitation of legacy flaws, abuse of Dropbox for PlugX configuration, and PowerShell launched through malicious .LNK files across the region.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published findings on the long-running MILE TEA campaign, describing its targeting of Japanese and Taiwanese organizations and its use of Elirks, Micrass, and Logedrut malware.
Unit 42 found that the CVE-2015-5122 exploit dropped and executed IsSpace, a Trojan they assessed as a likely evolution of the NFlog backdoor based on code and behavioral similarities.
On July 16, 2015, Unit 42 discovered that attackers had compromised a well-known aerospace firm's website to serve a weaponized Adobe Flash exploit for CVE-2015-5122 to the firm's customers.
Palo Alto Networks Unit 42 reported that the 2015 DragonOK phishing campaign used Sysget as a first-stage payload and staged multiple backdoors, including PlugX and a newly identified custom RAT named FormerFirstRAT.
Blue Termite expanded beyond spear-phishing to compromise Japanese websites and deliver a Flash exploit for CVE-2015-5119 in drive-by-download attacks, including targeting tied to Japanese government visitors. Kaspersky linked the activity to Emdivi malware, with emdivi t17 used as the infection/backdoor component and emdivi t20 deployed post-compromise.
Between January and March 2015, DragonOK carried out five phishing attacks delivering Sysget/HelloBridge malware against a Japanese manufacturing firm, with the final wave also targeting a Japanese high-tech organization.
Trend Micro said threat actors used a Type II PlugX RAT variant that abused Dropbox as a download site for command-and-control settings in June 2014.
Trend Micro reported that spear-phishing remained the dominant infection vector in targeted attacks across Asia-Pacific in the first half of 2014, with watering-hole attacks also observed.
Unit 42 reported that the MILE TEA campaign's target base shifted toward Japan in mid-2013 after earlier attacks were more often reported from Taiwan.
Palo Alto Networks Unit 42 observed the MILE TEA cyber-espionage campaign as early as 2011, primarily targeting organizations in Japan and Taiwan using spear-phishing and custom malware.
The campaign exploiting CVE-2016-7836 in SKYSEA Client View ran from June 2016 until February 2019, using malware including Wali and NodeRAT.
The SKYSEA Client View exploitation campaign resumed on 15 March 2018 after a lull, continuing BRONZE BUTLER's use of CVE-2016-7836 against Japanese targets.
BRONZE BUTLER, also known as Tick, exploited SKYSEA Client View vulnerability CVE-2016-7836 as a zero-day in a campaign targeting Japanese IP space.
Attackers exploited Ichitaro vulnerability CVE-2014-7247 as a zero-day through targeted emails sent to Japanese government agencies and enterprises, delivering malware including Emdivi, PlugX, and Agtid.
APT actors exploited Sanshiro vulnerability CVE-2014-0810 as a zero-day against Japanese government agencies, delivering PlugX through spear-phishing emails with malicious .jsd documents.
JPCERT/CC observed the same actor using Adobe Flash, Microsoft Word, Ichitaro, and Sanshiro exploits in spear-phishing campaigns targeting Japan from at least 2013 to early 2014.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourcesecurelist.com
Open sourceunit42.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcevirusbulletin.com
Open sourcedocs.microsoft.com
Open sourcedocuments.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.