logo

Attack Exploiting Legitimate Service by APT-C-60

ID: 183896c3-57ae-5a4e-8d55-8e57d9cc8e7e

STIX ID: report--183896c3-57ae-5a4e-8d55-8e57d9cc8e7e

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2024-12-11

Date Updated: 2026-04-19

Author: 亀井 智矢(Tomoya Kamei)

...
...

JPCERT/CC reports that in August 2024 APT-C-60 likely targeted a Japanese organization using a spearphishing email posing as a job applicant; victims downloaded a VHDX from Google Drive containing LNKs that launched a downloader (SecureBootUEFI.dat) which abused StatCounter and Bitbucket to retrieve and execute a multi-stage payload culminating in the SpyGlace backdoor. The analysis details infection flow, downloader and backdoor behavior, persistence via COM hijacking, C2 infrastructure and URLs, commands, and a list of malware hashes and related IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.