Also known as: Operation RestyLink, Enelink
Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails with malicious attachments to gain initial access to their targets' systems. Earth Yako's objectives and patterns suggest a possible connection to a Chinese APT group, but conclusive proof of their nationality is lacking. They have been observed using various malware delivery methods and techniques, such as the use of Winword.exe for DLL Hijacking.
Executive Summary
Earth Yako is a threat actor targeting researchers in Japanese academic institutions and think tanks through spearphishing campaigns. They use malicious attachments and DLL hijacking via Winword.exe for initial access. While their link to a Chinese APT group is speculative, their tactics align with state-sponsored espionage objectives.
Goals & Targeting
Earth Yako’s targeting of academic and think tank researchers in Japan suggests a focus on intellectual property theft, sensitive research data exfiltration, or long-term surveillance of geopolitical analysis. The lack of overt financial motives and the actor’s technical capabilities imply a strategic objective aligned with state-sponsored espionage. Victims are likely selected based on their access to high-value research, policy development, or technological innovation relevant to national security interests.
Enhanced Description
Earth Yako, also known as Operation RestyLink and Enelink, has been identified targeting researchers within academic organizations and think tanks in Japan. Their primary method involves spearphishing emails containing malicious attachments designed to exploit document-based vulnerabilities. Technical analysis reveals the use of Winword.exe for DLL hijacking, a technique that enables arbitrary code execution on compromised systems. Although the actor’s geopolitical affiliation remains unproven, their operational patterns—such as focused targeting of intellectual assets and use of sophisticated payload delivery methods—suggest a possible connection to nation-state supported groups. The group’s activities lack overt financial motives, indicating potential strategic intelligence-gathering objectives. However, the absence of confirmed malware samples or attribution linkage limits definitive classification.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Yako’s campaigns exhibit a high degree of focus on Japanese academic and think tank environments, reflecting a targeted approach to extract sensitive intellectual assets. Operational tempo appears moderate, with no publicly reported large-scale breaches. Notable historical activity includes the use of document-based attacks leveraging Winword.exe, though no confirmed links to historical APT campaigns have been established. The actor’s reliance on spearphishing and limited infrastructure reuse suggests a low-and-slow operational strategy.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Earth Yako’s attribution is moderate due to the lack of confirmed malware samples, geographic attribution evidence, or direct linkage to known APT groups. While technical indicators like Winword.exe exploitation align with APT behaviors, the absence of unique malware signatures or geopolitical ties reduces certainty. Gaps include limited IOCs for malware analysis and no confirmed historical attacks beyond described patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics