Quick Summary
AllegedExecutive Summary
Corona Corporation, a Japanese company operating within the industrial and consumer product sectors, was identified as a victim on the MetaEncryptor ransomware group’s leak site on August 23, 2026. This listing signifies MetaEncryptor’s expansion into Japan, a country that has become one of the group’s documented top target nations, alongside the United States and Germany. The company’s inclusion on the leak site highlights its operations within a market that MetaEncryptor has actively pursued. In the preceding 60 days, MetaEncryptor has claimed responsibility for approximately seven victims, frequently targeting the Other, Manufacturing, and Agriculture and Food Production industries. The United States, Japan, and Germany are the primary geographic locations from which MetaEncryptor has sourced victims. Corona Corporation’s placement within Japan aligns with the ransomware group’s established targeting patterns in the Asia-Pacific region. While the group shows a tendency to target US-based entities, exemplified by victims like FactoryFive, Aquamar Inc., and Trailer Transit Inc., Corona Corporation represents a diversification into Asian markets, though it shares an “Other” industry classification with Woodlore International Inc. from Canada.
Technical Analysis
SOCRadar’s analysis involved querying its stealer-log telemetry for the domain corona.co.jp. The query, which covered a paginated sample, returned no records. It is critical to note that the absence of findings in this specific, limited sample does not confirm that the organization is unaffected. Potential limitations include the possibility of credentials existing under alternate corporate domains, the use of personal email aliases, or records that may not yet have been indexed. Furthermore, any compromised credentials could have been used and subsequently rotated before the indexing period of the queried dataset. Infostealer-harvested credentials are a well-established initial access vector for ransomware operations. While this particular query did not yield direct evidence of compromised credentials for corona.co.jp, this does not preclude their existence or potential use by threat actors. MetaEncryptor’s modus operandi is consistent with utilizing various entry points, including phishing campaigns, exploitation of exposed VPN appliances, and the reuse of compromised credentials. Therefore, organizations listed on such leak sites, irrespective of direct telemetry findings, should consider this an indication that the threat actor possesses actionable intelligence. Affected organizations are strongly advised to conduct thorough audits of their authentication logs. Implementing multi-factor authentication (MFA) on all internet-exposed services is paramount. Continuous dark web monitoring and proactive credential hygiene checks, including regular password rotations and review of MFA configurations for services like Microsoft 365, VPNs, and remote-access portals, are recommended actions to mitigate potential risks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.