The Spamhaus Project<p>❗We're observing a massive spam/phishing campaign targeting Japanese users 🇯🇵 — sent using a botnet of 3.5–4 million IPs, churning rapidly with ~250k new IPs added daily.</p><p>Just 650 unique subject lines have been observed, with many reused 100k+ times. Here's an example subject【お知らせ】春季キャンペーン特典の有効化手続きのお願い<br>Which translates to "[Notice] Request for activation procedure for spring campaign benefits"</p><p>📧 Most emails are sent from residential IPs in LATAM, North Africa, Russia/former Soviet states, and the Middle East.</p><p>The campaign appears to be phishing traffic formerly using Chinese networks 🎣 — now shifted to residential proxy networks after large Chinese ranges were listed.</p><p>We encourage National CERTs to reach out to Spamhaus directly at "cert-team@spamhaus.org" for additional information of what we are seeing within your constituency. A notice has also been sent to the <span class="h-card" translate="no"><a href="https://infosec.exchange/@firstdotorg" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>firstdotorg</span></a></span> community.</p><p>If you have connections with Japanese companies, please encourage them to watch out for phishing emails that appear to come from well-known brands - paypay, SBI, Amazon JCB, Apple Resona Bank, AEON, and ETC - but originate from suspicious, non-legitimate IP addresses.</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/spam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>spam</span></a> <a href="https://infosec.exchange/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>threatintel</span></a></p>