Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors EvilPost

Description

**Targets:** Japanese Defence Sector **Toolset/Malware:** CVE-2015-2545 **Notes:** C2 Server in Japan

Goals & Targeting

Targeted Sectors

Defense

Targeted Countries / Regions

JP

AI Analysis

· 1 week ago

Executive Summary

EvilPost is a nation-state level threat actor primarily focused on espionage activities targeting Japanese defense organizations. The group has demonstrated advanced capabilities, leveraging known vulnerabilities and employing sophisticated tactics to maintain persistence within targeted networks.

Goals & Targeting

EvilPost appears to be motivated by strategic espionage objectives, likely aligned with the interests of a nation-state. The sustained targeting of Japanese defense sector entities suggests an intent to gather classified information on military capabilities, defense policies, and technological advancements. This focus aligns with the broader goals of nation-state actors seeking to gain strategic advantages through intelligence acquisition.

Enhanced Description

EvilPost is a state-sponsored threat group that specializes in conducting espionage operations against government and defense sector entities in Japan. The actor was first identified as a persistent threat due to its strategic targeting of sensitive institutions and its use of advanced techniques to compromise systems. EvilPost's activities are indicative of a high level of organization and technical proficiency, with a particular focus on exfiltrating sensitive information. The group's toolset includes the exploitation of known vulnerabilities such as CVE-2015-2545, which suggests an interest in compromising critical systems through targeted attacks.

Key Capabilities

  • Exploitation of known vulnerabilities (e.g., CVE-2015-2545)
  • Advanced persistent threat (APT) tactics
  • Lateral movement within networks
  • Command and control (C2) infrastructure

MITRE ATT&CK Tactics

Reconnaissance
Espionage

ATT&CK Techniques

T1059
T1566
T1203
T1572

Software / Tooling

Adjudication Framework (Apt)

Campaigns & Victims

EvilPost has demonstrated a persistent and targeted approach to compromising Japanese defense organizations. The group's campaigns have been characterized by patient reconnaissance, tailored exploit development, and long-term persistence within target networks. While specific details of their past operations remain limited, EvilPost's activities suggest an ongoing interest in maintaining access to critical defense systems.

IOC Patterns

  • Use of phishing emails targeting defense sector employees
  • Exploitation of CVE-2015-2545 in Microsoft products
  • Command and control infrastructure located within Japan

Recommended Actions

  • Monitor for email communication patterns indicative of phishing campaigns.
  • Enforce strict controls on external device usage to prevent unauthorized access.
  • Implement endpoint detection and response (EDR) solutions to identify malicious activity.
  • Conduct regular network traffic analysis to detect异常通信 patterns.

Suggested Tags

APT
espionage
nation-state
defense-sector

Confidence Assessment

High confidence in the identification of EvilPost as a nation-state threat actor targeting Japanese defense organizations. Limited data availability regarding TTPs and exact APT39 ties introduces some uncertainty, but the pattern of behavior aligns strongly with state-sponsored activity.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
nation-state
defense-sector

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.