Japanese-Language Phishing Campaign — Coordinated Brand Impersonation (ANA, DHL, myTOKYOGAS) via .cn Domains, Foxmail X-Mailer Fingerprint, Chinese Infrastructure
Japanese-Language Phishing Campaign (TL-2026-0129), also tracked as Foxmail Japanese Phishing Campaign, is a medium-severity phishing campaign, first published 2026-02-22. It carries a reported China nexus and is not formally attributed, affects ANA Holdings ANA Mileage Club, maps to 21 MITRE ATT&CK techniques (T1036, T1041, T1056), and is covered by 9 detection rules and 21 indicators of compromise.
Key facts for TL-2026-0129
- Threat ID
- TL-2026-0129
- Also known as
- Foxmail Japanese Phishing Campaign, CN-Domain Brand Impersonation Campaign
- Severity
- MEDIUM
- Status
- MONITORING
- Category
- PHISHING
- First published
- 2026-02-22
- Last reviewed
- 2026-02-22
- Attribution confidence
- NONE
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- transportation, logistics, utilities, consumers, financial
- Target regions
- Japan, East Asia
- Detection rules
- 9
- Indicators of compromise
- 21
SANS ISC documented an ongoing coordinated phishing campaign targeting Japanese-speaking users through brand impersonation of ANA (All Nippon Airways), DHL, and myTOKYOGAS. All emails originate from Chinese .cn domains, use the identical X-Mailer fingerprint 'Foxmail 6, 13, 102, 15 [cn]' (Tencent's Chinese email client), and direct victims to credential-harvesting pages hosted on .cn TLD infrastructure. All three sending IPs (150.5.129.136, 101.47.78.193, 150.5.130.42) resolve to Hong Kong on AS150436 (Byteplus Pte. Ltd. — ByteDance cloud infrastructure), confirming a single coordinated operator. The campaign uses large-scale list-based distribution reaching non-Japanese speakers, suggesting broad reconnaissance via purchased or scraped email lists.
How Japanese-Language Phishing Campaign works
## Overview
On February 21, 2026, Brad Duncan at the SANS Internet Storm Center published analysis of a coordinated Japanese-language phishing campaign that impersonates multiple major brands including ANA (All Nippon Airways), DHL Express, and myTOKYOGAS (Tokyo Gas utility service). The campaign has been active for at least one year, targeting Japanese-speaking users with credential-harvesting emails and phishing pages.
## Infrastructure Analysis
### Sending Infrastructure
All three documented phishing emails originate from Hong Kong-based infrastructure on AS150436, operated by Byteplus Pte. Ltd. (a subsidiary of ByteDance, the parent company of TikTok). The three sending IPs — 150.5.129.136, 101.47.78.193, and 150.5.130.42 — all geolocate to the Yau Tsim Mong District of Hong Kong and share the same ASN. This indicates the campaign operator is renting cloud infrastructure from Byteplus to send phishing emails, leveraging the platform's reputation to bypass email filtering.
The sending domains are randomly generated .cn domains: - ncqjw.cn (sending ANA phish) - obpwnrl.cn (sending DHL phish) - cwqfvzp.cn (sending myTOKYOGAS phish)
These domains follow a pattern of short, random-character .cn registrations — a hallmark of Chinese-origin phishing infrastructure designed for disposability. Each domain is used briefly before being burned and replaced.
### Foxmail X-Mailer Fingerprint
The most significant attribution indicator is the consistent X-Mailer header across all samples: 'Foxmail 6, 13, 102, 15 [cn]'. Foxmail is a freeware email client developed by Tencent Holdings, with dominant market share in China. Version 6.x is a legacy release — the current version is 7.2.25 (September 2022). The use of this specific legacy version across all campaign emails confirms:
1. A single operator or coordinated group using the same email sending toolkit 2. Chinese-origin operation (Foxmail is predominantly used in China) 3. The [cn] locale tag confirms Chinese-language Foxmail installation 4. Legacy version suggests either an older automated sending setup or deliberate version pinning for compatibility with bulk-sending scripts
### Phishing Page Infrastructure
Phishing pages are hosted on .cn domains with randomized subdomain prefixes: - branchiish.aayjlc.cn/amcmembr_Loginam/ (ANA credential harvest) - decideosity.ykdyrkye.cn/portal_login_exp/getQuoteTab/ (DHL credential harvest) - impactish.rexqm.cn/mtgalogin/ (myTOKYOGAS credential harvest)
The URL path patterns are customized per brand but follow a consistent structure: randomized English-sounding subdomain + short random .cn domain + brand-specific path mimicking legitimate login endpoints.
## Brand Impersonation Analysis
### ANA (All Nippon Airways) Japan's largest airline by revenue. The phishing email impersonates ANA communications, likely targeting ANA Mileage Club members with messages about account verification, mileage expiration, or booking confirmations. The credential-harvesting page mimics ANA's AMC member login portal.
### DHL Express Global logistics and shipping company with significant operations in Japan. DHL phishing typically uses delivery notification lures — package tracking, customs clearance, or delivery scheduling. The URL path 'portal_login_exp/getQuoteTab/' suggests a shipping portal impersonation.
### myTOKYOGAS Tokyo Gas utility service portal. Targets Japanese residents who use Tokyo Gas for home energy. Phishing lure likely involves billing, account verification, or payment update notifications. The path 'mtgalogin/' directly references the myTOKYOGAS login abbreviation.
## Campaign Characteristics
### Scale and Distribution The campaign uses bulk distribution reaching non-Japanese speakers, as documented by the SANS researcher who received multiple phishing emails despite not being Japanese. This indicates: - Large email lists purchased or scraped without language filtering - High-volume, low-precision approach (spray and pray) - Willingness to burn sending domains quickly due to spam filter catches
### Operational Consistency Despite impersonating different brands, all emails share: - .cn sending domains (randomly generated) - .cn phishing page domains (randomly generated with English-sounding subdomains) - Identical X-Mailer: Foxmail 6, 13, 102, 15 [cn] - Same ASN (AS150436) for sending infrastructure - +0800 timezone in Date headers (UTC+8, consistent with China/Hong Kong) - Japanese language content with brand-specific lures
### Attribution Assessment The campaign is attributed with MEDIUM confidence to a Chinese-speaking threat group based on: - Foxmail Chinese-language client with [cn] locale - All infrastructure on .cn TLD - Sending IPs in Hong Kong (Byteplus/ByteDance cloud) - +0800 timezone in email headers - Operational pattern consistent with Chinese phishing-as-a-service ecosystems
The motivation is FINANCIAL — credential harvesting for ANA loyalty accounts (mileage fraud), DHL shipping accounts (logistics fraud), and utility accounts (payment card theft).
## Defensive Recommendations
### Immediate Actions - Block sending IPs: 150.5.129.136, 101.47.78.193, 150.5.130.42 at email gateway - Block .cn TLD in email sending domains for organizations not doing business with Chinese entities - Add X-Mailer 'Foxmail 6, 13, 102, 15' to email header-based detection rules - Block phishing domains: aayjlc.cn, ykdyrkye.cn, rexqm.cn, ncqjw.cn, obpwnrl.cn, cwqfvzp.cn
### Long-Term Defenses - Implement DMARC enforcement for impersonated brands (ANA, DHL, TOKYOGAS) - Deploy email gateway rules matching .cn TLD + Foxmail X-Mailer combination - User awareness training for Japanese-language phishing indicators - Monitor for new .cn domain registrations matching random-character patterns - Implement certificate transparency monitoring for brand domains
### Detection Opportunities - Email header analysis: X-Mailer fingerprint matching across diverse brand lures - URL pattern analysis: randomized English subdomain + short .cn domain + brand-specific path - Timezone analysis: +0800 offset in Date headers from non-Chinese-branded senders - ASN correlation: multiple phishing campaigns from AS150436 (Byteplus)
MITRE ATT&CK techniques used in TL-2026-0129
defense-evasion
T1036 Masquerading; T1550.004 Web Session Cookie; T1684.001 Impersonation
exfiltration
T1041 Exfiltration Over C2 Channel
collection
T1056 Input Capture; T1056.003 Web Portal Capture
command-and-control
execution
impact
credential-access
T1539 Steal Web Session Cookie; T1552.001 Credentials In Files
initial-access
T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service
resource-development
T1583.001 Domains; T1583.003 Virtual Private Server; T1585.002 Email Accounts; T1588.002 Tool; T1608.005 Link Target
reconnaissance
T1589.002 Email Addresses; T1593 Search Open Websites/Domains; T1598.003 Spearphishing Link
Affected products and versions in Japanese-Language Phishing Campaign
- ANA Holdings — ANA Mileage Club
Vulnerable versions: Web portal users - DHL Express — DHL Shipping Portal
Vulnerable versions: Web portal users - Tokyo Gas — myTOKYOGAS Portal
Vulnerable versions: Web portal users
Remediation for Japanese-Language Phishing Campaign
Immediate actions
- Block sending IPs at email gateway: 150.5.129.136, 101.47.78.193, 150.5.130.42
- Block phishing domains: aayjlc.cn, ykdyrkye.cn, rexqm.cn, ncqjw.cn, obpwnrl.cn, cwqfvzp.cn
- Add X-Mailer 'Foxmail 6, 13, 102, 15' to email header detection rules
- Alert employees of ANA, DHL, myTOKYOGAS brand impersonation phishing
- Block .cn TLD in email sending domains if not business-critical
Workarounds
- Block all .cn TLD emails at gateway for organizations not operating in China
- Quarantine emails with X-Mailer containing 'Foxmail' and [cn] locale tag
- Flag emails with +0800 timezone from non-Chinese brand senders
Longer-term hardening
- Implement DMARC enforcement for impersonated brands
- Deploy email gateway rules matching .cn TLD + Foxmail X-Mailer combination
- Japanese-language phishing awareness training for at-risk users
- Monitor for new .cn domain registrations matching random-character patterns
- Implement certificate transparency monitoring for brand domains
- Deploy email authentication (SPF/DKIM/DMARC) validation at gateway
Weaknesses (CWE) in Japanese-Language Phishing Campaign
CWE-451
Timeline of Japanese-Language Phishing Campaign
- Campaign estimated to have begun approximately one year before SANS ISC publication, based on researcher's statement of receiving emails 'for at least the past year or so'. Source: https://isc.sans.edu/diary/rss/32734
- ANA (All Nippon Airways) phishing email sent from ncqjw.cn (150.5.129.136) at 21:52:36 +0800. X-Mailer: Foxmail 6, 13, 102, 15 [cn]. Source: SANS ISC diary 32734
- myTOKYOGAS phishing email sent from cwqfvzp.cn (150.5.130.42) at 23:50:56 +0800. X-Mailer: Foxmail 6, 13, 102, 15 [cn]. Source: SANS ISC diary 32734
- DHL phishing email sent from obpwnrl.cn (101.47.78.193) at 12:29:35 +0800. X-Mailer: Foxmail 6, 13, 102, 15 [cn]. Source: SANS ISC diary 32734
- Brad Duncan publishes SANS ISC diary entry 32734 documenting the coordinated Japanese-language phishing campaign with IOCs and screenshots. Source: https://isc.sans.edu/diary/rss/32734
- Threadlinqs Intelligence Platform publishes TL-2026-0129 with infrastructure analysis confirming all sending IPs on AS150436 (Byteplus/ByteDance cloud, Hong Kong).
- As of 2026-05-29, this credential-harvesting phishing operation (Foxmail [cn] X-Mailer, .cn brand-impersonation of ANA/DHL/myTOKYOGAS) remains active with no takedown, arrest, or operator disruption reported. SANS ISC 32734 (Feb 21) documented year-long activity, and Google GTIG/Help Net Security (May 26) confirm the Chinese-language PhaaS ecosystem—including YY Lai Yu's 400+ Japanese brand templates—is expanding, though the specific burn-and-replace .cn domains are perishable.
Sources cited for Japanese-Language Phishing Campaign
- SANS ISC: Japanese-Language Phishing Emails (Brad Duncan)
- SANS ISC: Phishing Email Screenshot — ANA Impersonation
- SANS ISC: Phishing Email Screenshot — DHL Impersonation
- SANS ISC: Phishing Email Screenshot — myTOKYOGAS Impersonation
- Wikipedia: Foxmail (Tencent Email Client)
- IPinfo: AS150436 Byteplus Pte. Ltd. — Sending IP Geolocation
- OWASP: Phishing Attack Techniques
- ANA Official Website
- DHL Express Official
- myTOKYOGAS Official Portal
More in phishing
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration
- Bad Sushi: China-Nexus Phishing Operation Shifts to Residential Proxy Networks
- Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters
- Finance-Themed Phishing Evolves to Operationally Styled, Process-Mimicking Lures (Cofense, Q1 2025-Q1 2026)
Detection coverage for TL-2026-0129
As of 2026-02-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0129 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.