Japanese-Language Phishing Campaign — Coordinated Brand Impersonation (ANA, DHL, myTOKYOGAS) via .cn Domains, Foxmail X-Mailer Fingerprint, Chinese Infrastructure

Japanese-Language Phishing Campaign (TL-2026-0129), also tracked as Foxmail Japanese Phishing Campaign, is a medium-severity phishing campaign, first published 2026-02-22. It carries a reported China nexus and is not formally attributed, affects ANA Holdings ANA Mileage Club, maps to 21 MITRE ATT&CK techniques (T1036, T1041, T1056), and is covered by 9 detection rules and 21 indicators of compromise.

Key facts for TL-2026-0129

Threat ID
TL-2026-0129
Also known as
Foxmail Japanese Phishing Campaign, CN-Domain Brand Impersonation Campaign
Severity
MEDIUM
Status
MONITORING
Category
PHISHING
First published
2026-02-22
Last reviewed
2026-02-22
Attribution confidence
NONE
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
transportation, logistics, utilities, consumers, financial
Target regions
Japan, East Asia
Detection rules
9
Indicators of compromise
21

SANS ISC documented an ongoing coordinated phishing campaign targeting Japanese-speaking users through brand impersonation of ANA (All Nippon Airways), DHL, and myTOKYOGAS. All emails originate from Chinese .cn domains, use the identical X-Mailer fingerprint 'Foxmail 6, 13, 102, 15 [cn]' (Tencent's Chinese email client), and direct victims to credential-harvesting pages hosted on .cn TLD infrastructure. All three sending IPs (150.5.129.136, 101.47.78.193, 150.5.130.42) resolve to Hong Kong on AS150436 (Byteplus Pte. Ltd. — ByteDance cloud infrastructure), confirming a single coordinated operator. The campaign uses large-scale list-based distribution reaching non-Japanese speakers, suggesting broad reconnaissance via purchased or scraped email lists.

How Japanese-Language Phishing Campaign works

## Overview

On February 21, 2026, Brad Duncan at the SANS Internet Storm Center published analysis of a coordinated Japanese-language phishing campaign that impersonates multiple major brands including ANA (All Nippon Airways), DHL Express, and myTOKYOGAS (Tokyo Gas utility service). The campaign has been active for at least one year, targeting Japanese-speaking users with credential-harvesting emails and phishing pages.

## Infrastructure Analysis

### Sending Infrastructure

All three documented phishing emails originate from Hong Kong-based infrastructure on AS150436, operated by Byteplus Pte. Ltd. (a subsidiary of ByteDance, the parent company of TikTok). The three sending IPs — 150.5.129.136, 101.47.78.193, and 150.5.130.42 — all geolocate to the Yau Tsim Mong District of Hong Kong and share the same ASN. This indicates the campaign operator is renting cloud infrastructure from Byteplus to send phishing emails, leveraging the platform's reputation to bypass email filtering.

The sending domains are randomly generated .cn domains: - ncqjw.cn (sending ANA phish) - obpwnrl.cn (sending DHL phish) - cwqfvzp.cn (sending myTOKYOGAS phish)

These domains follow a pattern of short, random-character .cn registrations — a hallmark of Chinese-origin phishing infrastructure designed for disposability. Each domain is used briefly before being burned and replaced.

### Foxmail X-Mailer Fingerprint

The most significant attribution indicator is the consistent X-Mailer header across all samples: 'Foxmail 6, 13, 102, 15 [cn]'. Foxmail is a freeware email client developed by Tencent Holdings, with dominant market share in China. Version 6.x is a legacy release — the current version is 7.2.25 (September 2022). The use of this specific legacy version across all campaign emails confirms:

1. A single operator or coordinated group using the same email sending toolkit 2. Chinese-origin operation (Foxmail is predominantly used in China) 3. The [cn] locale tag confirms Chinese-language Foxmail installation 4. Legacy version suggests either an older automated sending setup or deliberate version pinning for compatibility with bulk-sending scripts

### Phishing Page Infrastructure

Phishing pages are hosted on .cn domains with randomized subdomain prefixes: - branchiish.aayjlc.cn/amcmembr_Loginam/ (ANA credential harvest) - decideosity.ykdyrkye.cn/portal_login_exp/getQuoteTab/ (DHL credential harvest) - impactish.rexqm.cn/mtgalogin/ (myTOKYOGAS credential harvest)

The URL path patterns are customized per brand but follow a consistent structure: randomized English-sounding subdomain + short random .cn domain + brand-specific path mimicking legitimate login endpoints.

## Brand Impersonation Analysis

### ANA (All Nippon Airways) Japan's largest airline by revenue. The phishing email impersonates ANA communications, likely targeting ANA Mileage Club members with messages about account verification, mileage expiration, or booking confirmations. The credential-harvesting page mimics ANA's AMC member login portal.

### DHL Express Global logistics and shipping company with significant operations in Japan. DHL phishing typically uses delivery notification lures — package tracking, customs clearance, or delivery scheduling. The URL path 'portal_login_exp/getQuoteTab/' suggests a shipping portal impersonation.

### myTOKYOGAS Tokyo Gas utility service portal. Targets Japanese residents who use Tokyo Gas for home energy. Phishing lure likely involves billing, account verification, or payment update notifications. The path 'mtgalogin/' directly references the myTOKYOGAS login abbreviation.

## Campaign Characteristics

### Scale and Distribution The campaign uses bulk distribution reaching non-Japanese speakers, as documented by the SANS researcher who received multiple phishing emails despite not being Japanese. This indicates: - Large email lists purchased or scraped without language filtering - High-volume, low-precision approach (spray and pray) - Willingness to burn sending domains quickly due to spam filter catches

### Operational Consistency Despite impersonating different brands, all emails share: - .cn sending domains (randomly generated) - .cn phishing page domains (randomly generated with English-sounding subdomains) - Identical X-Mailer: Foxmail 6, 13, 102, 15 [cn] - Same ASN (AS150436) for sending infrastructure - +0800 timezone in Date headers (UTC+8, consistent with China/Hong Kong) - Japanese language content with brand-specific lures

### Attribution Assessment The campaign is attributed with MEDIUM confidence to a Chinese-speaking threat group based on: - Foxmail Chinese-language client with [cn] locale - All infrastructure on .cn TLD - Sending IPs in Hong Kong (Byteplus/ByteDance cloud) - +0800 timezone in email headers - Operational pattern consistent with Chinese phishing-as-a-service ecosystems

The motivation is FINANCIAL — credential harvesting for ANA loyalty accounts (mileage fraud), DHL shipping accounts (logistics fraud), and utility accounts (payment card theft).

## Defensive Recommendations

### Immediate Actions - Block sending IPs: 150.5.129.136, 101.47.78.193, 150.5.130.42 at email gateway - Block .cn TLD in email sending domains for organizations not doing business with Chinese entities - Add X-Mailer 'Foxmail 6, 13, 102, 15' to email header-based detection rules - Block phishing domains: aayjlc.cn, ykdyrkye.cn, rexqm.cn, ncqjw.cn, obpwnrl.cn, cwqfvzp.cn

### Long-Term Defenses - Implement DMARC enforcement for impersonated brands (ANA, DHL, TOKYOGAS) - Deploy email gateway rules matching .cn TLD + Foxmail X-Mailer combination - User awareness training for Japanese-language phishing indicators - Monitor for new .cn domain registrations matching random-character patterns - Implement certificate transparency monitoring for brand domains

### Detection Opportunities - Email header analysis: X-Mailer fingerprint matching across diverse brand lures - URL pattern analysis: randomized English subdomain + short .cn domain + brand-specific path - Timezone analysis: +0800 offset in Date headers from non-Chinese-branded senders - ASN correlation: multiple phishing campaigns from AS150436 (Byteplus)

MITRE ATT&CK techniques used in TL-2026-0129

defense-evasion

T1036 Masquerading; T1550.004 Web Session Cookie; T1684.001 Impersonation

exfiltration

T1041 Exfiltration Over C2 Channel

collection

T1056 Input Capture; T1056.003 Web Portal Capture

command-and-control

T1071.001 Web Protocols

execution

T1204.001 Malicious Link

impact

T1531 Account Access Removal

credential-access

T1539 Steal Web Session Cookie; T1552.001 Credentials In Files

initial-access

T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service

resource-development

T1583.001 Domains; T1583.003 Virtual Private Server; T1585.002 Email Accounts; T1588.002 Tool; T1608.005 Link Target

reconnaissance

T1589.002 Email Addresses; T1593 Search Open Websites/Domains; T1598.003 Spearphishing Link

Affected products and versions in Japanese-Language Phishing Campaign

  • ANA Holdings — ANA Mileage Club
    Vulnerable versions: Web portal users
  • DHL Express — DHL Shipping Portal
    Vulnerable versions: Web portal users
  • Tokyo Gas — myTOKYOGAS Portal
    Vulnerable versions: Web portal users

Remediation for Japanese-Language Phishing Campaign

Immediate actions

  • Block sending IPs at email gateway: 150.5.129.136, 101.47.78.193, 150.5.130.42
  • Block phishing domains: aayjlc.cn, ykdyrkye.cn, rexqm.cn, ncqjw.cn, obpwnrl.cn, cwqfvzp.cn
  • Add X-Mailer 'Foxmail 6, 13, 102, 15' to email header detection rules
  • Alert employees of ANA, DHL, myTOKYOGAS brand impersonation phishing
  • Block .cn TLD in email sending domains if not business-critical

Workarounds

  • Block all .cn TLD emails at gateway for organizations not operating in China
  • Quarantine emails with X-Mailer containing 'Foxmail' and [cn] locale tag
  • Flag emails with +0800 timezone from non-Chinese brand senders

Longer-term hardening

  • Implement DMARC enforcement for impersonated brands
  • Deploy email gateway rules matching .cn TLD + Foxmail X-Mailer combination
  • Japanese-language phishing awareness training for at-risk users
  • Monitor for new .cn domain registrations matching random-character patterns
  • Implement certificate transparency monitoring for brand domains
  • Deploy email authentication (SPF/DKIM/DMARC) validation at gateway

Weaknesses (CWE) in Japanese-Language Phishing Campaign

CWE-451

Timeline of Japanese-Language Phishing Campaign

  • Campaign estimated to have begun approximately one year before SANS ISC publication, based on researcher's statement of receiving emails 'for at least the past year or so'. Source: https://isc.sans.edu/diary/rss/32734
  • ANA (All Nippon Airways) phishing email sent from ncqjw.cn (150.5.129.136) at 21:52:36 +0800. X-Mailer: Foxmail 6, 13, 102, 15 [cn]. Source: SANS ISC diary 32734
  • myTOKYOGAS phishing email sent from cwqfvzp.cn (150.5.130.42) at 23:50:56 +0800. X-Mailer: Foxmail 6, 13, 102, 15 [cn]. Source: SANS ISC diary 32734
  • DHL phishing email sent from obpwnrl.cn (101.47.78.193) at 12:29:35 +0800. X-Mailer: Foxmail 6, 13, 102, 15 [cn]. Source: SANS ISC diary 32734
  • Brad Duncan publishes SANS ISC diary entry 32734 documenting the coordinated Japanese-language phishing campaign with IOCs and screenshots. Source: https://isc.sans.edu/diary/rss/32734
  • Threadlinqs Intelligence Platform publishes TL-2026-0129 with infrastructure analysis confirming all sending IPs on AS150436 (Byteplus/ByteDance cloud, Hong Kong).
  • As of 2026-05-29, this credential-harvesting phishing operation (Foxmail [cn] X-Mailer, .cn brand-impersonation of ANA/DHL/myTOKYOGAS) remains active with no takedown, arrest, or operator disruption reported. SANS ISC 32734 (Feb 21) documented year-long activity, and Google GTIG/Help Net Security (May 26) confirm the Chinese-language PhaaS ecosystem—including YY Lai Yu's 400+ Japanese brand templates—is expanding, though the specific burn-and-replace .cn domains are perishable.

Sources cited for Japanese-Language Phishing Campaign

More in phishing

Detection coverage for TL-2026-0129

As of 2026-02-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0129 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats