Operation RestyLink - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:33:18 UTC Home > List all groups > Operation RestyLink APT group: Operation RestyLink Names Operation RestyLink (NTT) Operation Enelink (?) Earth Yako (Trend Micro) Country [Unknown] Motivation Information theft and espionage First seen 2021 Description (NTT) Our SOC observed APT campaign targeting Japanese companies starting from mid of April 2022. We think that this campaign had already started in March 2022 and related attack might have performed around October 2021. It implies that this campaign is not temporary nor intensive, and it could continue from here forward. Observed Countries: Japan. Tools used Information Last change to this card: 17 February 2023 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=77129bef-3a35-4ebb-a51e-fb04b22fcb25 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=77129bef-3a35-4ebb-a51e-fb04b22fcb25 Page 1 of 1