Earth Yako targets researchers in Japan with spearphishing campaigns, possibly linked to Chinese APT groups.
Analyst brief
Earth Yako, also known as Operation RestyLink, is a threat actor targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails with malicious attachments to gain initial access. Key TTPs include exploiting Winword.exe for DLL Hijacking, suggesting a possible connection to Chinese APT groups, though attribution remains unconfirmed. Defenders should focus on detecting suspicious email attachments, monitoring Word process behavior, and hunting for DLL loading anomalies leading to remote code execution.
Earth Yako
Operation RestyLinkEnelink
unknown
Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails with malicious attachments to gain initial access to their targets' systems. Earth Yako's objectives and patterns suggest a possible connection to a Chinese APT group, but conclusive proof of their nationality is lacking. They have been observed using various malware delivery methods and techniques, such as the use of Winword.exe for DLL Hijacking.