APT-C-60 Campaign: Malicious VHDX Hosted on Google Drive Lures Job Applicants
ID: 8bf90e58-bb22-53c2-985c-b7548f0f31e7
STIX ID: report--8bf90e58-bb22-53c2-985c-b7548f0f31e7
Feed Name: GBHackers
JPCERT/CC warns of an active APT-C-60 campaign targeting recruitment staff in Japan and East Asia that uses spear-phishing with weaponized VHDX attachments; when mounted, an embedded LNK abuses the legitimate Git component gcmd.exe to execute scripts and deploy the SpyGlace framework. The actors persist via COM hijacking (CLSID {566296fe-e0e8-475f-ba9c-a31ad31620b1}), use StatCounter checks combined with GitHub-hosted configs for device identification and payload distribution, and rapidly iterate SpyGlace (versions 3.1.12–3.1.14) with custom crypto and anti-analysis features—making network detection difficult and requiring monitoring of VHDX attachments, unusual StatCounter/GitHub traffic, and COM-hijacking behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
