Blue Termite, Cloudy Omega
Description
(Kaspersky) In October 2014, Kaspersky Lab started to research “Blue Termite”, an Advanced Persistent Threat (APT) targeting Japan. The oldest sample we’ve seen up to now is from November 2013.
This is not the first time the country has been a victim of an APT. However, the attack is different in two respects: unlike other APTs, the main focus of Blue Termite is to attack Japanese organizations; and most of their C2s are located in Japan. One of the top targets is the Japan Pension Service, but the list of targeted industries includes government and government agencies, local governments, public interest groups, universities, banks, financial services, energy, communication, heavy industry, chemical, automotive, electrical, news media, information services sector, health care, real estate, food, semiconductor, robotics, construction, insurance, transportation and so on. Unfortunately, the attack is still active and the number of victims has been increasing.
Names
Name | Name-Giver |
---|---|
Blue Termite | Kaspersky |
Cloudy Omega | Symantec |
Country
Motivation
- Information theft and espionage
First Seen
2013
Observed Sectors
- Automotive
- Chemical
- Construction
- Education
- Energy
- Financial
- Food and Agriculture
- Government
- Healthcare
- High-Tech
- Industrial
- IT
- Media
- Telecommunications
- Transportation
- Real estate and several others
Observed Countries
Tools
Information
- https://securelist.com/new-activity-of-the-blue-termite-apt/71876/
- https://www.symantec.com/connect/blogs/operation-cloudyomega-ichitaro-zero-day-and-ongoing-cyberespionage-campaign-targeting-japan
Other Information
Uuid
320ddce3-12ab-49df-b578-ebaef364b288
Last Card Change
2020-04-15