Spot the Difference: Earth Kasha’s New LODEINFO Campaign And The Correlation Analysis With The APT10 Umbrella


LODEINFO is a malware used in attacks targeting mainly Japan since 2019. Trend Micro has been tracking the group as Earth Kasha. While some vendors suspect that the actor using LODEINFO might be APT10, we don’t have enough evidence to fully support this speculation.

Currently, we view APT10 and Earth Kasha as different entities, although they might be related. To avoid confusion caused by names, we use a new term “APT10 Umbrella,” which represents a group of intrusion sets related to APT10 (including APT10 itself). Earth Kasha has been known to have targeted public institutions and academics with spear-phishing emails since their emergence. From early 2023 to early 2024, however, we identified a new campaign with significant updates to their strategy, tactics, and arsenals.

Read more…
Source: Trend Micro


Sign up for our Newsletter


Related:

  • ClickFix attacks are tricking Mac and Windows users into hacking themselves

    September 14, 2026

    If you clicked on an HBO Max ad on Reddit over the past week, you might want to check your computer for malware. These so-called “ClickFix” attacks have quickly become one of the rising cybersecurity threats of 2026, and they’re getting both sneakier and compromising people’s devices with greater frequency. Until recently, ClickFix attacks were a ...

  • OpenAI’s malicious bot swarm attacked RubyGems

    September 14, 2026

    OpenAI agents appear to have flooded RubyGems with malicious packages, adding to a near-daily deluge of rogue AI models engaging in potentially unlawful activity while their human creators face growing questions over responsibility for their agents’ bad behavior. A swarm of agents began uploading malware to the Ruby package registry on May 5, and flooded RubyGems with more than 2,000 malicious packages between May ...

  • Revolut confirms customer data breach through fake government requests

    September 12, 2026

    British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including ...

  • The modern bank heist is already under way

    September 11, 2026

    The image of the bank robber is hopelessly outdated. Today’s heist does not begin with a getaway car outside a branch. It begins quietly, with an adversary establishing persistence inside a financial institution’s network and studying how the organisation responds, says Tom Kellermann, VP of AI Security and Threat Research at Trend AI. The objective is no longer ...

  • A new Android attack combines malware and ransomware in a cocktail of cybercrime

    September 11, 2026

    Unique malware variant spotted targeting Android users. When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. Rarely do we see all of these functionalities merged into a single entity, and even rarer – to have it target Android ...

  • ShinyHunters expose 6.4M in attack on medical supplier McKesson

    September 10, 2026

    McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP ...