logo

Update on Attacks by Threat Group APT-C-60

ID: 4ac03cc9-224e-5b59-8bf2-1cf75e48f7c8

STIX ID: report--4ac03cc9-224e-5b59-8bf2-1cf75e48f7c8

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2025-11-05

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

JPCERT/CC documents a targeted spear‑phishing campaign (attributed to APT‑C‑60) against recruitment staff in Japan that uses malicious VHDX attachments containing LNK files which execute Git to run scripts, deploy a persistent downloader via COM hijacking, and fetch SpyGlace payloads hosted on GitHub; the report describes downloader and SpyGlace updates, their encoding/C2 schemes (custom RC4/BASE64/RC4 variant, AES-128-CBC), decoy documents, and observable GitHub timelines for the malware versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.