Japanese-Language Phishing Campaign — Coordinated Brand Impersonation (ANA, DHL, myTOKYOGAS) via .cn Domains, Foxmail X-Mailer Fingerprint, Chinese Infrastructure — Threadlinqs Intelligence
As of 2026-05-30, Japanese-Language Phishing Campaign — Coordinated Brand Impersonation (ANA, DHL, myTOKYOGAS) via .cn Domains, Foxmail X-Mailer Fingerprint, Chinese Infrastructure is a medium-severity phishing threat attributed to a China-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0129 · Severity: MEDIUM · Status: MONITORING · Category: PHISHING
Attribution: China · FINANCIAL
SANS ISC documented an ongoing coordinated phishing campaign targeting Japanese-speaking users through brand impersonation of ANA (All Nippon Airways), DHL, and myTOKYOGAS. All emails originate from
## Overview
On February 21, 2026, Brad Duncan at the SANS Internet Storm Center published analysis of a coordinated Japanese-language phishing campaign that impersonates multiple major brands including ANA (All Nippon Airways), DHL Express, and myTOKYOGAS (Tokyo Gas utility service). The campaign has been active for at least one year, targeting Japanese-speaking users with credential-harvesting emails and phishing pages.
## Infrastructure Analysis
### Sending Infrastructure
All three documented phishing emails originate from Hong Kong-based infrastructure on AS150436, operated by Byteplus Pte. Ltd. (a subsidiary of ByteDance, the parent company of TikTok). The three sending IPs — 150.5.129.136, 101.47.78.193, and 150.5.130.42 — all geolocate to the Yau Tsim Mong District of Hong Kong and share the same ASN. This indicates the campaign operator is renting cloud infrastructure from Byteplus to send phishing emails, leveraging the platform's reputation to bypass email filtering.
The sending domains are randomly generated .cn domains:
- ncqjw.cn (sending ANA phish)
- obpwnrl.cn (sending DHL phish)
- cwqfvzp.cn (sending myTOKYOGAS phish)
These domains follow a pattern of short, random-character .cn registrations — a hallmark of Chinese-origin phishing infrastructure designed for disposability. Each domain is used briefly before being burned and replaced.
### Foxmail X-Mailer Fingerprint
The most significant attribution indicator is the consistent X-Mailer header across all samples: 'Foxmail 6, 13, 102, 15 [cn]'. Foxmail is a freeware email client developed by Tencent Holdings, with dominant market share in China. Version 6.x is a legacy release — the current version is 7.2.25 (September 2022). The use of this specific legacy version across all campaign emails confirms:
1. A single operator or coordinated group using the same email sending toolkit
2. Chinese-origin operation (Foxmail is predominantly used in China)
3. The [cn] locale tag confirms Chinese-language Foxmail installation
4. Legacy version suggests either an older automated sending setup or deliberate version pinning for compatibility with bulk-sending scripts
### Phishing Page Infrastructure
Phishing pages are hosted on .cn domains with randomized subdomain prefixes:
- branchiish.aayjlc.cn/amcmembr_Loginam/ (ANA credential harvest)
- decideosity.ykdyrkye.cn/portal_login_exp/getQuoteTab/ (DHL credential harvest)
- impactish.rexqm.cn/mtgalogin/ (myTOKYOGAS credential harvest)
The URL path patterns are customized per brand but follow a consistent structure: randomized English-sounding subdomain + short random .cn domain + brand-specific path mimicking legitimate login endpoints.
## Brand Impersonation Analysis
### ANA (All Nippon Airways)
Japan's largest airline by revenue. The phishing email impersonates ANA communications, likely targeting ANA Mileage Club members with messages about account verification, mileage expiration, or booking confirmations. The credential-harvesting page mimics ANA's AMC member login portal.
### DHL Express
Global logistics and shipping company with significant operations in Japan. DHL phishing typically uses delivery notification lures — package tracking, customs clearance, or delivery scheduling. The URL path 'portal_login_exp/getQuoteTab/' suggests a shipping portal impersonation.
### myTOKYOGAS
Tokyo Gas utility service portal. Targets Japanese residents who use Tokyo Gas for home energy. Phishing lure likely involves billing, account verification, or payment update notifications. The path 'mtgalogin/' directly references the myTOKYOGAS login abbreviation.
## Campaign Characteristics
### Scale and Distribution
The campaign uses bulk distribution reaching non-Japanese speakers, as documented by the SANS researcher who received multiple phishing emails despite not being Japanese. This indicates:
- Large email lists purchased or scraped without language filtering
- High-volume, low-precision approach (spray and pray)
- Willin
Target sectors: transportation, logistics, utilities, consumers, financial
Target regions: Japan, East Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1589.002, T1593, T1583.001, T1583.003, T1588.002, T1608.005, T1585.002, T1566.002, T1566.003, T1204.001