Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cyberwarfare

Japan Links Chinese Hacker MirrorFace to Dozens of Cyberattacks Targeting Security and Tech Data

Japan says China-linked cyberattacks were systematic attacks with an aim of stealing data on Japanese national security and advanced technology.

APT24 BadAudio supply-chain

Japan on Wednesday linked more than 200 cyberattacks over the past five years targeting the country’s national security and high technology data to a Chinese hacking group, MirrorFace, detailing their tactics and calling on government agencies and businesses to reinforce preventive measures.

The National Police Agency said its analysis on the targets, methods and infrastructure of the cyberattacks by MirrorFace from 2019 to 2024 concluded they were systematic attacks linked to China with an aim of stealing data on Japanese national security and advanced technology.

The targets of the Chinese government-led cyberattacks included Japan’s Foreign and Defense ministries, the country’s space agency and individuals including politicians, journalists, private companies and think tanks related to advanced technology, the NPA said.

Experts have repeatedly raised concerns about the vulnerability of Japan’s cybersecurity, especially as the country steps up its defense capabilities and works more closely with the United States and other partners to strengthen cyber defenses. Japan has taken steps but experts say more work is needed.

MirrorFace sent emails with attachments containing malware to targeted organizations and individuals to view data saved on computers mainly from December 2019 to July 2023, often from Gmail and Microsoft Outlook addresses using stolen identities, the NPA investigation found.

The emails typically used as subjects key words such as “Japan-U.S. alliance,” “Taiwan Strait,” “Russia-Ukraine war” and “free and open Indo-Pacific,” and included an invitation for a study panel, references and a list of panelists, the NPA said.

Advertisement. Scroll to continue reading.

In another tactic, the hackers targeted Japanese organizations in areas of aerospace, semiconductors, information and communications from February to October 2023 by exploiting vulnerabilities in virtual private networks to gain unauthorized access to information.

The attacks included one on the Japan Aerospace and Exploration Agency, or JAXA, which acknowledged in June it had suffered a series of cyberattacks since 2023, though sensitive information related to rockets, satellites and defense was not affected. It was investigating to take preventive measures.

Last year, a cyberattack paralyzed operations at a container terminal at a port in the city of Nagoya for three days.

More recently, Japan Airlines was hit by a cyberattack on Christmas, causing delays and cancellations to more than 20 domestic flights, though the carrier was able to stop the onslaught and restore its systems hours later and there was no impact on flight safety.

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.