[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies
- May 26
- 4 min read


This Week's Security Threat Highlights
The threats identified this week have once again highlighted the importance of continuously monitoring for anomalies rather than waiting until an intrusion has occurred.
The new banking malware uses Telegram to immediately initiate remote control, and Chinese threat groups exploit legitimate services to maintain a long-term presence. Furthermore, ransomware attacks continue to target Japanese companies, and advancements in AI-based vulnerability detection technology are bringing about significant changes in both attack and defense strategies.
As attackers' methods become more sophisticated, businesses need not just a "one-time diagnosis," but "continuous monitoring and improvement." Let's look at this week's major threats.
[Threat 1] Bank Ghost Banking Malware: Targeting Japan and Other Countries
The threat actor named 'Infrastructure Destruction Squad' has developed a new version of their banking malware 'BankGhost'. Price $400 dollars with 3 weeks of support, and every week the tool is further developed. The malware supports 30 full remote control commands including spying on camera and microphone, stealing passwords, files, cookies, Wi-Fi passwords, Discord tokens, Telegram sessions, WhatsApp data and crypto wallets in addition to executing CMD and PowerShell commands disabling antivirus and firewall, enabling RDP and full file control. After the victim runs the file on their device, hacker will receive an instant notification via Telegram bot containing complete device information including computer name, username, IP address and the target bank from that moment. Hacker can send any command via Telegram and take full remote control over the victim system with ease. Main features include a complete and easy to use graphical interface and support for more than 700 banks worldwide. Supported banks include from USA, UK, Canada, Australia, Germany, France, Brazil, Mexico, Japan, India, UAE, Saudi Arabia, Singapore, South Africa, Turkey, Switzerland, Italy, Spain, Netherlands, and Scandinavian countries.
[Threat 2] Gentlemen Ransomware: Listed New Victim from Japan
The Gentlemen ransomware group has added 1 new Japanese victim to their dark web portal.
Source: Pipeline DarkWeb Monitoring
[Threat 3] Mustang Panda’s Advanced Cyber Espionage Campaign Targeting Asia-Pacific Organizations
A China-linked threat group known as Mustang Panda conducted a long-running cyber espionage campaign targeting organizations across the Asia-Pacific region and Japan between September 2025 and April 2026. The attackers mainly focused on sectors such as finance and used advanced stealth techniques to avoid detection. The campaign relied on an updated version of the FDMTP backdoor, a heavily obfuscated .NET malware designed for remote control and espionage activities. Attackers impersonated trusted Yahoo and Apple CDN domains to distribute malicious payloads. They also used DLL sideloading by combining legitimate executables with malicious DLL files, allowing malware to run inside trusted processes. The malware operates mostly in memory, reducing traces on the disk and making detection harder. Once executed, the backdoor communicated through a custom TCP-based DMTP protocol with persistent command capabilities. The framework supported modular plugins for persistence, registry modification, scheduled task creation, remote file retrieval, and process manipulation. Persistence was maintained through scheduled tasks and registry keys under Microsoft IME paths. The malware frequently contacted CDN-like domains every five minutes for updates and instructions. Researchers noted that the attackers regularly changed infrastructure and indicators, limiting the effectiveness of traditional IOC-based detection. Security experts therefore recommend behavior-based monitoring and detection strategies to identify attack patterns rather than relying only on static signatures.
[News 4] Japan Orders Cybersecurity Review Over AI Bug-Hunting Tools Like Anthropic’s Mythos Amid Rising Security Concerns
Japan’s Prime Minister Sanae Takaichi ordered a nationwide cybersecurity review due to concerns about rapidly advancing AI-based vulnerability-hunting systems such as Anthropic Mythos. The directive tasks cybersecurity minister Hisashi Matsumoto with evaluating whether government systems can effectively detect and patch security weaknesses. It also calls for a broader review of national cybersecurity readiness across public infrastructure. A key focus is ensuring that operators of critical infrastructure can strengthen their defenses against emerging threats. The concern driving the review is that AI tools could significantly accelerate both the discovery and exploitation of software vulnerabilities. This acceleration could increase the scale and speed of cyberattacks targeting essential systems. The article notes that researchers and cybersecurity vendors have long warned about AI enabling more automated offensive capabilities. Mythos, released in April 2026, has intensified these discussions by bringing the issue into mainstream policy attention. At the same time, some experts argue that Mythos mainly improves speed rather than enabling entirely new categories of vulnerabilities. Overall, Japan’s response reflects growing global concern that AI-driven cyber operations could reshape the threat landscape and require stronger, proactive defenses.
Recommendations:
Train staff not to open unexpected files; verify senders before acting
Add dual-approval controls on all wire transfers and large payments
Update your ransomware incident response plan and assign clear decision owners
Review cyber insurance to confirm ransomware and data breach costs are covered
Identify your most sensitive data (M&A, client records) and treat it as already at risk from silent espionage
Block unauthorized executables and outbound Telegram traffic at the network perimeter
Shift from IOC/signature-based detection to behavior-based EDR/XDR—attackers rotate indicators constantly
Enforce offline, air-gapped backups and test restoration quarterly

Finally
AI environments are often presented as "tools,"
The moment they are made public, they become assets that carry the exact same risks as servers.
The recent GHOST campaign is a classic example of an attack that exploits this perception gap.
First, start by checking how your company's AI environment looks from the outside.
Thank you for reading this far.
We at PIPELINE Corporation are a group of experts specializing in cybersecurity and threat intelligence.
We face threats together with our customers on-site every day.
"Even if we have a specialized team within the company, we lack the resources," "We don't know where to start," and "We want to prepare realistically, assuming we will be attacked."
We receive many inquiries like this. Regardless of the size of the company, the current situation is that weak points in defenses are easily targeted.
Furthermore, trying to handle everything internally inevitably makes it easier for things to be overlooked.
That's why we focus on practical methods that are useful in the field, rather than idealistic theories, and propose a small-scale, easy-to-implement approach. Even "a small step within your capabilities" can make a big difference in safety.
If you have any concerns at all, please feel free to contact us. Let's work together to find the quickest way to strengthen your security.
![[Office Tour] Introducing PIPELINE's New Office](https://static.wixstatic.com/media/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.webp)
![[Office Tour] Introducing PIPELINE's New Office](https://static.wixstatic.com/media/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.webp)


![[June 2026] Top 4 Cybersecurity Incidents Impacting Japanese Companies | BEC Fraud, Ransomware, and Supply Chain Attacks PIPELINE](https://static.wixstatic.com/media/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.png/v1/fill/w_366,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.webp)
![[June 2026] Top 4 Cybersecurity Incidents Impacting Japanese Companies | BEC Fraud, Ransomware, and Supply Chain Attacks PIPELINE](https://static.wixstatic.com/media/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.png/v1/fill/w_980,h_670,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.webp)

![[June 2026] Top 4 Cybersecurity Incidents Impacting Japanese Companies | BEC Fraud, Ransomware, and Supply Chain Attacks PIPELINE](https://static.wixstatic.com/media/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.png)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png)
![[Week 3 of May 2026] Four New Threats Japanese Companies Should Be Wary of: Canvas breach, npm supply chain attack, and ClaudeBleed](https://static.wixstatic.com/media/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png/v1/fill/w_980,h_513,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/95ec1f_f5d30c2fc79344eb8199da2390a2c1c3~mv2.png)
![[Office Tour] Introducing PIPELINE's New Office](https://static.wixstatic.com/media/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.webp)
![[Office Tour] Introducing PIPELINE's New Office](https://static.wixstatic.com/media/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_21ed61f221564db88de347d4cfc232c0~mv2.webp)


![[June 2026] Top 4 Cybersecurity Incidents Impacting Japanese Companies | BEC Fraud, Ransomware, and Supply Chain Attacks PIPELINE](https://static.wixstatic.com/media/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.webp)
![[June 2026] Top 4 Cybersecurity Incidents Impacting Japanese Companies | BEC Fraud, Ransomware, and Supply Chain Attacks PIPELINE](https://static.wixstatic.com/media/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_7f54d00c113f4af6aea7dbf08e02bc9d~mv2.webp)
![[Press Release] Collaboration with 7 domestic companies to strengthen supply chain security PIPELINE](https://static.wixstatic.com/media/95ec1f_80d22e109c86451f93bd6e9ad0702803~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_80d22e109c86451f93bd6e9ad0702803~mv2.webp)
![[Press Release] Collaboration with 7 domestic companies to strengthen supply chain security PIPELINE](https://static.wixstatic.com/media/95ec1f_80d22e109c86451f93bd6e9ad0702803~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_80d22e109c86451f93bd6e9ad0702803~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[2nd Week of June 2026] From Zero-Day Attacks to State-Sponsored Attacks: 4 Latest Threats Targeting Japanese Companies PIPELINE](https://static.wixstatic.com/media/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_77789520e7b54469970eebdda4caea9c~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_444,h_250,fp_0.50_0.50,q_35,blur_30,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)
![[5th Week of May 2026] Attacks are becoming more automated – 4 of the latest cyber threats targeting Japanese companies](https://static.wixstatic.com/media/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.png/v1/fill/w_385,h_217,fp_0.50_0.50,q_95,enc_avif,quality_auto/95ec1f_13c273711c304fd2b2893f20be1f2e08~mv2.webp)