Earth Yako

Aliases: Operation RestyLink, Enelink

Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:13:57

Targeted industries: education-and-nonprofits government-and-public-sector

Targeted regions: country_code:jp

Context

Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails with malicious attachments to gain initial access to their targets' systems. Earth Yako's objectives and patterns suggest a possible connection to a Chinese APT group, but conclusive proof of their nationality is lacking. They have been observed using various malware delivery methods and techniques, such as the use of Winword.exe for DLL Hijacking.

Reports & references

  • Trend Micro — Invitation To Secret Event Uncovering Earth Yako Campaigns (report)

External references