APT-C-60 refreshes SpyGlace loader chain
APT-C-60 continues spear-phishing Japanese recruiters with VHDX attachments that deploy updated SpyGlace malware via GitHub and statcounter for C2.
JPCERT/CC reports continued activity by APT-C-60 between June and August 2025, targeting Japanese recruitment staff with spear-phishing emails impersonating job applicants. Unlike prior campaigns that used Google Drive links, the group now attaches malicious VHDX files directly to emails; opening the embedded LNK triggers a legitimate Git binary (gcmd.exe) to execute a hidden script that drops a decoy document and a first-stage downloader (WebClassUser.dat), persisted via COM hijacking.
The downloader chain has been updated to fingerprint victims using volume serial number and computer name, check in with the legitimate analytics service statcounter.com, and retrieve second-stage payload locations from attacker-controlled files hosted on a GitHub repository (carolab989/class2025). This second downloader retrieves and executes the SpyGlace backdoor and its loader, both using updated XOR/ADD-based API resolution and COM hijacking for persistence. JPCERT/CC identified three SpyGlace builds (3.1.12–3.1.14) with modified commands, a new 'uld' module-unload function, and changed persistence paths, alongside a distinct C2 protocol combining BASE64 and a modified RC4 cipher with the identifying string 'GOLDBAR' previously linked to this actor.
The campaign shows continuity with APT-C-60 operations observed in 2024 and overlaps in TTPs with a separate overseas campaign reported in September 2025, though infrastructure does not overlap, suggesting parallel or forked operations. The reliance on legitimate services (Git, GitHub, statcounter) for staging and C2 complicates detection and reflects deliberate operational security by the group.
Mentioned in this report
Source reporting: https://blogs.jpcert.or.jp/en/2025/11/APT-C-60_update.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free