VORANT. Threat Intelligence Sign in Get the full feed

JSAC2026 Day 1: China-nexus APT campaigns detailed

medium threat government-nationalfinancial-serviceseducationhealthcaretelecommunicationsmanufacturing

JPCERT/CC's JSAC2026 conference detailed multiple China- and North Korea-linked APT campaigns, including Earth Krahang, Earth Kurma, Tianwu, and Konni, plus mass Ivanti exploitation.

JPCERT/CC's JSAC2026 conference (Jan 21-23, 2026) featured presentations from Trend Micro, Palo Alto Networks, Cisco Talos, TeamT5, Cycraft, IIJ, LAC, and ITOCHU covering a broad range of nation-state intrusion activity. Highlights included the PONDSNAKE and WILYCODE campaigns linked to Earth Krahang and Earth Lusca (both associated with the leaked Chinese contractor i-Soon), targeting government, financial, education, and healthcare organizations via public-facing server exploitation and spear-phishing, deploying tools such as SnakeC2, NEOBEACON, Cobalt Strike, and VShell. Palo Alto Networks presented a multi-cluster attribution case study involving CL-STA-1048 (possible Earth Estries links), CL-STA-1049 (attributed to Unfading Sea Haze), and a Stately Taurus cluster, illustrating the challenges of overlapping Chinese APT toolsets under a 'Premier Pass-as-a-Service' collaboration model.

Additional sessions detailed Earth Kurma's stealthy persistence and exfiltration techniques abusing OneDrive, Dropbox, and Webex against Southeast Asian government and telecom targets; the continued evolution of Tianwu's Pangolin8RAT and custom Cobalt Strike Beacon since 2022 with intensified activity from October 2024; and a Cycraft-analyzed Chinese state-sponsored intrusion against Taiwanese government and manufacturing sectors using Microsoft Graph API C2 laundering, dead-drop resolvers, and AD logon script abuse for malware distribution (GRAPHBROTLI, GRAPHRELOOK, RCREMARK). LAC researchers detailed GSRAT, an AutoIt-based RAT tied to North Korea's Konni group, used in spear-phishing against Korean financial-sector affiliates.

Separately, TeamT5 reported large-scale exploitation of Ivanti Connect Secure devices — over 170 compromised systems across 25 regions concentrated in Japan, Taiwan, South Korea, and the US — involving the SPAWN malware suite, the TextDoor in-memory backdoor, and DebtTheft credential theft, alongside forensic challenges from encrypted partitions and GUI-limited logging. A Tropic Trooper-attributed case demonstrated a DNS-hijacking supply-chain-style attack in which a compromised home router redirected legitimate application updates to a malicious server, underscoring risks in trusted update mechanisms.

Mentioned in this report

Vulnerabilities CVE-2025-55182KEV
Threat actors Earth EstriesEarth KrahangEarth KurmaEarth LuscaKonniStately TaurusTianwuTropic TrooperUnfading Sea Haze
Malware Cobalt StrikeCoolClientEggStreme LoaderFluffyGh0stGorem RATHyperBro LauncherHypnosis LoaderKRNRATMMLOADMasol RATMoriyaNEOBEACONPUBLOADRawCookieSnakeC2SoftEther VPNVShell

Source reporting: https://blogs.jpcert.or.jp/en/2026/02/jsac2026day1.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free