[April 2026 Week 2] Japan Cyber Threat Report : Malware Trends and Security Insights
- Apr 7
- 3 min read
Updated: Apr 10

Japan Cyber Threat Report, Week 2 of April 2026
In April 2026, cyber threats in Japan remain active. What this ranking reveals is a shift from traditional "system-destroying attacks" to attacks targeting authentication credentials and data .
The following malware programs are particularly noteworthy:
Rank | Malware name | number |
1 | Tycoon 2FA | 134,770 |
2 | Emotot | 121,775 |
3 | Agent Tesla | 54,487 |
4 | EvilProxy | 50,555 |
5 | njRAT | 49,517 |
6 | RedLine | 46,793 |
7 | Lumma | 45,185 |
8 | AsyncRAT | 44,434 |
9 | Remcos | 41,997 |
10 | XWorm | 40,365 |

Illustrated: Trends in the Japan region over the past 14 days, based on publicly available data from the malware analysis platform ANY.RUN.
These rankings are based on actual observational data and show which threats are currently being used most frequently in reality .
This month's threat highlights
① Increase in attacks targeting authentication credentials
What we can see from the increase in "Tycoon 2FA" is,
Not a system intrusion
Increase in attacks aiming to bypass authentication
is.
In other words
「ログインできれば勝ち」The attack has changed to this.
② Spread of information-stealing malware
The following types of malware are on the rise:
RedLine
Lumma
Agent Tesla
these are
Browser saved information
password
Session Information
It specializes in extracting [something].
③ Continued use of remotely controlled malware
AsyncRAT
njRAT
Remcos
These are still widely used.
The reason is simple
Easy to install
Can remain dormant for a long period of time
Difficult to discover
That's why.
Impact on Japanese companies
What we can see from this trend is
「侵入されるか」ではなく「どう使われるか」This represents a shift in perspective.
In other words
Silent intrusion
Used without being noticed
The damage is spreading.
That's the general flow.
especially
Business partners
supply chain
The impact on this cannot be ignored.
5 Security Measures You Can Implement on-Site Right Now
① Strengthening account management
Thorough implementation of multi-factor authentication
Minimizing administrator privileges
Monitoring for suspicious logins
② Check for leakage of authentication information
Regularly change your password
Leak confirmed
Monitoring of external data leaks
③ Detection of suspicious behavior
Detection of communication anomalies
File access monitoring
Confirmation of unknown processes
④ Endpoint protection
Installing security software
Blocking suspicious files
phishing countermeasures
⑤ Supply chain countermeasures
Security check of the outsourced company
Setting minimum standards
Visualization of external risks
What PIPELINE can do
Malware detection and anomaly detection
RiskSensor visualizes externally visible risks and suspicious communications.
Investigation of unauthorized access
ThreatIDR analyzes traces of the attack to determine the intrusion route and the extent of the impact.
Information leakage prevention measures
DatalaiQ monitors data flow and prevents unauthorized data exfiltration.
summary
Cyberattacks in 2026
From “Destructive Attacks” to “Stealing Attacks”And it has changed significantly.
Many companies
The system is protected.
We are taking measures.
That's what I think, but in reality
Cases of intrusion that occur invisibly are also increasing.
notice
This 30-minute video clearly explains the process of obtaining a ★3 rating under the SCS (Supply Chain Security Measures) evaluation system. Please register and watch the video.

✦ Finally
Thank you for reading this far.
We at PIPELINE Corporation are a group of experts specializing in cybersecurity and threat intelligence.
We face threats together with our customers on-site every day.
"Even if we have a specialized team within the company, we lack the resources," "We don't know where to start," and "We want to prepare realistically, assuming we will be attacked."
We receive many inquiries like this. Regardless of the size of the company, the current situation is that weak points in defenses are easily targeted.
Furthermore, trying to handle everything internally inevitably makes it easier for things to be overlooked.
That's why we focus on practical methods that are useful in the field, rather than idealistic theories, and propose a small-scale, easy-to-implement approach. Even "a small step within your capabilities" can make a big difference in safety.
If you have any concerns at all, please feel free to contact us. Let's work together to find the quickest way to strengthen your security.
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)

![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.webp)
![[Third Week of May 2026] Four Incidents at Japanese Companies: From GitHub Credential Leaks to Ransomware Attacks](https://static.wixstatic.com/media/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.webp)
![[Third Week of May 2026] Four Incidents at Japanese Companies: From GitHub Credential Leaks to Ransomware Attacks](https://static.wixstatic.com/media/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_e00e67a4854b4a8882a13950e4a7a324~mv2.webp)
![[Week 2 of May 2026] Top 4 Cyber Threats Targeting Japanese Companies | npm Supply Chain Attacks, Fake AI Extensions & DNS Hijacking PIPELINE](https://static.wixstatic.com/media/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.webp)
![[Week 2 of May 2026] Top 4 Cyber Threats Targeting Japanese Companies | npm Supply Chain Attacks, Fake AI Extensions & DNS Hijacking PIPELINE](https://static.wixstatic.com/media/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_df7cf37dcaa7470da1331eac6e21b25c~mv2.webp)
![[April 4th Week, 2026] Top 3 Incidents at Japanese Companies: Simultaneous Multiple Attacks on Unauthorized Access, Ransomware, and Overseas Bases PIPELINE](https://static.wixstatic.com/media/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.webp)
![[April 4th Week, 2026] Top 3 Incidents at Japanese Companies: Simultaneous Multiple Attacks on Unauthorized Access, Ransomware, and Overseas Bases PIPELINE](https://static.wixstatic.com/media/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_d9fa7aad0cbd48fca7833df843dffbd0~mv2.webp)