Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Blue Termite

Also known as: Emdivi, Cloudy Omega

Description

**Targets:** This threat actor is believed to have been responsible for the Japan Pension Service incident. It is also known as Emdivi and Cloudy Omega. **Toolset/Malware:** Emdivi **Operations:** Blue Termite **Notes:** Possible link to APT10

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

JP

AI Analysis

· 1 week ago

Executive Summary

Blue Termite, also known as Emdivi and Cloudy Omega, is a nation-state-sponsored threat actor primarily involved in espionage activities targeting government sectors. It is linked to the Japan Pension Service incident and possibly associated with APT10. The group employs sophisticated tactics and tools, including malware and spear-phishing campaigns, to achieve its objectives.

Goals & Targeting

Blue Termite's primary strategic objective appears to be espionage, targeting government entities to gather sensitive information. The group's focus on Japan indicates a specific geopolitical interest or mandate, possibly linked to regional surveillance or intelligence collection. The choice of victims reflects the actor's ability to prioritize high-value targets in critical sectors.

Enhanced Description

Blue Termite, identified by multiple aliases including Emdivi and Cloudy Omega, represents a nation-state-sponsored cyber threat actor focused on espionage activities. The actor has been implicated in several high-profile incidents, most notably the compromise of the Japan Pension Service. This operation underscores Blue Termite's ability to target critical government infrastructure with precision. The group's toolset includes custom malware, which is consistent with advanced persistent threat (APT) behavior. Blue Termite's campaigns often involve sophisticated techniques such as spear-phishing and malicious software deployment to gain unauthorized access to sensitive systems. The actor's operational framework suggests a high level of organization and technical proficiency, aligning with the capabilities of state-sponsored groups.

Key Capabilities

  • Spear-phishing campaigns
  • Malware development and deployment
  • Persistent access tactics
  • Data exfiltration capabilities
  • Sophisticated espionage tools

MITRE ATT&CK Tactics

Espionage
Initial Access

Software / Tooling

Emdivi

Campaigns & Victims

Blue Termite is known for its targeted campaigns against government and critical infrastructure entities. The group's operations include the Japan Pension Service incident, which highlights its ability to exploit vulnerabilities in public sector systems. Campaign patterns suggest a focus on long-term access and data collection, consistent with APT behavior.

IOC Patterns

  • Spear-phishing emails
  • Malicious Office documents
  • Custom malware deployments
  • Hashes associated with Emdivi files

Recommended Actions

  • Implement strict email filtering to detect spear-phishing attempts.
  • Monitor for known malicious hash signatures in network traffic.
  • Conduct regular vulnerability assessments on critical systems.
  • Enforce least privilege principles to mitigate malware impact.

Suggested Tags

APT
espionage
government

Confidence Assessment

The available data provides sufficient context about Blue Termite's activities, particularly its involvement in the Japan Pension Service incident. However, gaps exist regarding the group's first seen and last seen timestamps, as well as specific details on their tools and techniques.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 9 SHA-1 Hash 9 URL 2

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

2

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
government

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.