logo

APT-C-60 Deploys Updated SpyGlace Malware In Japan Espionage

ID: 59d3b804-f50d-5dbf-a435-15906bd41966

STIX ID: report--59d3b804-f50d-5dbf-a435-15906bd41966

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2025-11-17

Date Updated: 2026-07-16

...
...

APT-C-60 ran a Q3 2025 campaign targeting Japanese organizations using socially engineered job-application lures that delivered VHDX attachments which, when mounted, executed Git-based droppers to install multi-stage SpyGlace backdoors (versions 3.1.12–3.1.14). The campaign abused legitimate services (StatCounter, GitHub) for victim tracking and selective payload delivery, used COM hijacking for persistence, custom RC4/AES-based encryption for C2 and payloads, and left multiple actionable indicators (registry paths, mutexes, GitHub timestamps) for defenders to hunt and block.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.