Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Yako

Also known as: Operation RestyLink, Enelink

Description

Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails with malicious attachments to gain initial access to their targets' systems. Earth Yako's objectives and patterns suggest a possible connection to a Chinese APT group, but conclusive proof of their nationality is lacking. They have been observed using various malware delivery methods and techniques, such as the use of Winword.exe for DLL Hijacking.

AI Analysis

· 1 week ago

Executive Summary

Earth Yako is a threat actor targeting researchers in Japanese academic institutions and think tanks through spearphishing campaigns. They use malicious attachments and DLL hijacking via Winword.exe for initial access. While their link to a Chinese APT group is speculative, their tactics align with state-sponsored espionage objectives.

Goals & Targeting

Earth Yako’s targeting of academic and think tank researchers in Japan suggests a focus on intellectual property theft, sensitive research data exfiltration, or long-term surveillance of geopolitical analysis. The lack of overt financial motives and the actor’s technical capabilities imply a strategic objective aligned with state-sponsored espionage. Victims are likely selected based on their access to high-value research, policy development, or technological innovation relevant to national security interests.

Enhanced Description

Earth Yako, also known as Operation RestyLink and Enelink, has been identified targeting researchers within academic organizations and think tanks in Japan. Their primary method involves spearphishing emails containing malicious attachments designed to exploit document-based vulnerabilities. Technical analysis reveals the use of Winword.exe for DLL hijacking, a technique that enables arbitrary code execution on compromised systems. Although the actor’s geopolitical affiliation remains unproven, their operational patterns—such as focused targeting of intellectual assets and use of sophisticated payload delivery methods—suggest a possible connection to nation-state supported groups. The group’s activities lack overt financial motives, indicating potential strategic intelligence-gathering objectives. However, the absence of confirmed malware samples or attribution linkage limits definitive classification.

Key Capabilities

  • Spearphishing campaigns with malicious document attachments
  • DLL hijacking via Winword.exe exploitation
  • Document-based payload delivery mechanisms
  • Social engineering targeting of academic and think tank personnel

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion

ATT&CK Techniques

T1059.003 (Command and Scripting Interpreter: Windows Command Shell)
T1192.001 (Software Deployment Tools: Malicious Document)
T1055 (Process Injection)
T1070 (Indicator Removal on Host)

Software / Tooling

Winword.exe (exploited for DLL hijacking)
Custom malware (unconfirmed family names)
Malicious Office documents with embedded payloads

Campaigns & Victims

Earth Yako’s campaigns exhibit a high degree of focus on Japanese academic and think tank environments, reflecting a targeted approach to extract sensitive intellectual assets. Operational tempo appears moderate, with no publicly reported large-scale breaches. Notable historical activity includes the use of document-based attacks leveraging Winword.exe, though no confirmed links to historical APT campaigns have been established. The actor’s reliance on spearphishing and limited infrastructure reuse suggests a low-and-slow operational strategy.

IOC Patterns

  • Spearphishing emails with malicious Office document attachments
  • DLL hijacking via Winword.exe exploitation
  • Custom malware payloads tailored to academic environments

Recommended Actions

  • Implement advanced email filtering with attachment sandboxing for Office documents
  • Conduct regular security awareness training focused on spearphishing detection
  • Monitor for lateral movement via DLL hijacking anomalies in Winword.exe processes
  • Deploy endpoint detection and response (EDR) tools to detect process injection behaviors
  • Analyze network traffic for unusual DNS queries or C2 activity related to Japanese target sectors

Suggested Tags

APT
Espionage
Academic sector
Japan
Spear-phishing
DLL hijacking

Confidence Assessment

Confidence in Earth Yako’s attribution is moderate due to the lack of confirmed malware samples, geographic attribution evidence, or direct linkage to known APT groups. While technical indicators like Winword.exe exploitation align with APT behaviors, the absence of unique malware signatures or geopolitical ties reduces certainty. Gaps include limited IOCs for malware analysis and no confirmed historical attacks beyond described patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Phishing
Espionage
Academic sector
Japan
Spear-phishing
DLL hijacking

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.