Yahoo! News Japan reported about tons of cases of securities account hijacking in May 2025.1 Cybercriminals were said to have sold stocks without their rightful owners’ permission. And between January and April 2025, more than 3,500 fraudulent transactions have already been recorded. Worse? Affected stock owners have already lost ¥300+ billion.
A report on the possible tool used to phish the stock owners identified seven domains as indicators of compromise (IoCs). We used this data, along with other information from various reports on similar phishing campaigns to identify more connected artifacts and other pertinent information.
Our in-depth analysis found:
- 36 registrant-connected domains
- 7,437 email-connected domains, 267 were malicious
- Seven string-connected domains
- 609 look-alike domains found using a similar domain algorithm covering 11 April–22 May 2025
- 47,232 look-alike domains found on First Watch covering January 2024–May 2025
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://news.yahoo.co.jp/articles/b733b79407bafa09b874e595549aef12e2b8fc60
- [2] https://www.proofpoint.com/us/blog/threat-insight/cogui-phish-kit-targets-japan-millions-messages