# JSAC2026 Day 1: China-nexus APT campaigns detailed

Published: 2026-02-20 · Severity: medium · Sectors: government-national, financial-services, education, healthcare, telecommunications, manufacturing
Canonical: https://vorant.io/reports/fc4dfe78-e19d-586d-a032-31353e44a304/jsac2026-day-1-china-nexus-apt-campaigns-detailed

> JPCERT/CC's JSAC2026 conference detailed multiple China- and North Korea-linked APT campaigns, including Earth Krahang, Earth Kurma, Tianwu, and Konni, plus mass Ivanti exploitation.

JPCERT/CC's JSAC2026 conference (Jan 21-23, 2026) featured presentations from Trend Micro, Palo Alto Networks, Cisco Talos, TeamT5, Cycraft, IIJ, LAC, and ITOCHU covering a broad range of nation-state intrusion activity. Highlights included the PONDSNAKE and WILYCODE campaigns linked to Earth Krahang and Earth Lusca (both associated with the leaked Chinese contractor i-Soon), targeting government, financial, education, and healthcare organizations via public-facing server exploitation and spear-phishing, deploying tools such as SnakeC2, NEOBEACON, Cobalt Strike, and VShell. Palo Alto Networks presented a multi-cluster attribution case study involving CL-STA-1048 (possible Earth Estries links), CL-STA-1049 (attributed to Unfading Sea Haze), and a Stately Taurus cluster, illustrating the challenges of overlapping Chinese APT toolsets under a 'Premier Pass-as-a-Service' collaboration model.

Additional sessions detailed Earth Kurma's stealthy persistence and exfiltration techniques abusing OneDrive, Dropbox, and Webex against Southeast Asian government and telecom targets; the continued evolution of Tianwu's Pangolin8RAT and custom Cobalt Strike Beacon since 2022 with intensified activity from October 2024; and a Cycraft-analyzed Chinese state-sponsored intrusion against Taiwanese government and manufacturing sectors using Microsoft Graph API C2 laundering, dead-drop resolvers, and AD logon script abuse for malware distribution (GRAPHBROTLI, GRAPHRELOOK, RCREMARK). LAC researchers detailed GSRAT, an AutoIt-based RAT tied to North Korea's Konni group, used in spear-phishing against Korean financial-sector affiliates.

Separately, TeamT5 reported large-scale exploitation of Ivanti Connect Secure devices — over 170 compromised systems across 25 regions concentrated in Japan, Taiwan, South Korea, and the US — involving the SPAWN malware suite, the TextDoor in-memory backdoor, and DebtTheft credential theft, alongside forensic challenges from encrypted partitions and GUI-limited logging. A Tropic Trooper-attributed case demonstrated a DNS-hijacking supply-chain-style attack in which a compromised home router redirected legitimate application updates to a malicious server, underscoring risks in trusted update mechanisms.

## Mentioned in this report

- Vulnerabilities: CVE-2025-55182 (KEV)
- Threat actors: Earth Estries, Earth Krahang, Earth Kurma, Earth Lusca, Konni, Stately Taurus, Tianwu, Tropic Trooper, Unfading Sea Haze
- Malware: Cobalt Strike, CoolClient, EggStreme Loader, FluffyGh0st, Gorem RAT, HyperBro Launcher, Hypnosis Loader, KRNRAT, MMLOAD, Masol RAT, Moriya, NEOBEACON, PUBLOAD, RawCookie, SnakeC2, SoftEther VPN, VShell

Source reporting: https://blogs.jpcert.or.jp/en/2026/02/jsac2026day1.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fc4dfe78-e19d-586d-a032-31353e44a304/jsac2026-day-1-china-nexus-apt-campaigns-detailed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
