Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
APT-C-60’s August 2024 operation combined a recruitment-themed phishing email, a Google Drive-hosted VHDX disk image, a malicious Windows shortcut, and trusted online services to deploy the SpyGlace backdoor against an unnamed Japanese organization. StatCounter helped the attackers identify victims, while Bitbucket staged additional malware components. The campaign was not simply a WPS Office exploit: its success depended on social engineering, user execution, Windows-native tools, COM hijacking, and abuse of legitimate cloud and developer platforms.
This article describes the 2024 campaign and separates it from related APT-C-60 activity reported in 2025 and 2026.
What happened in the APT-C-60 campaign?
According to JPCERT/CC’s analysis, a recruiting contact at an unnamed Japanese organization received an email that appeared to come from a prospective employee. The message directed the recipient to a file hosted on Google Drive.
The download was a VHDX virtual-disk image. After it was mounted, the image exposed a decoy document and a shortcut named Self-Introduction.lnk. The shortcut used the legitimate git.exe executable to launch the next stage while opening the decoy document, helping the activity appear routine to the victim.
#1 Best Overall
The resulting chain was:
Recruitment-themed email
↓
Google Drive-hosted VHDX
↓
Self-Introduction.lnk + decoy document
↓
git.exe launches script activity
↓
SecureBootUEFI.dat
↓
StatCounter victim identification
↓
Bitbucket retrieves Service.dat
↓
cbmp.txt and icon.txt become cn.dat and sp.dat
↓
COM hijacking persistence
↓
SpyGlace backdoor
JPCERT/CC identified the analyzed backdoor as SpyGlace, sample version 3.1.6. Earlier coverage used the spelling “SpyGrace”; JPCERT/CC corrected the name in a September 1, 2025 update.
How the infection chain worked
1. A convincing job-application lure
The attacker’s choice of a recruiting scenario was important. A recipient involved in hiring may reasonably expect unsolicited résumés, self-introductions, portfolios, or other documents from applicants. That context reduced the suspicion normally associated with an unexpected executable.
The decoy document served a second purpose: it gave the user something plausible to see after opening the shortcut while the malicious stages ran in the background.
2. A VHDX file concealed the shortcut
A VHDX file is a virtual hard-disk image, not inherently a malware format. It can be used legitimately for virtual machines, software deployment, and testing. In this case, however, the image acted as a container for the malicious LNK file and decoy content.
Disk images can complicate email and endpoint inspection because the dangerous shortcut is inside the mounted volume rather than presented directly as the initial attachment. Organizations that allow VHD or VHDX use should still treat disk images delivered through unsolicited email or unfamiliar cloud-storage links as high-risk.
3. The LNK launched trusted Windows activity
Self-Introduction.lnk initiated script and payload activity through the legitimate git.exe executable. The chain also involved a file identified as IPML.txt, which created the downloader and decoy activity.
This is a classic detection challenge: the presence of git.exe is not suspicious by itself. Developers may use it every day. The stronger signal is the combination of a mounted VHDX, an LNK, unusual parent-child relationships, script execution, and subsequent connections to StatCounter and Bitbucket.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute4. SecureBootUEFI.dat contacted StatCounter
The downloader, saved as SecureBootUEFI.dat, contacted StatCounter before retrieving the next stage. JPCERT/CC reported that it placed a victim-specific string in the HTTP Referer header.
The value incorporated the computer name, the home directory, and a value derived from the computer name and username. Nonalphabetic characters were removed, and the result was encoded using XOR 3. This gave the attackers a way to distinguish individual infected systems.
StatCounter therefore played a victim-identification or signaling role in the reported chain. Calling it the complete command-and-control channel would be misleading. Bitbucket staged additional payloads, while separate infrastructure handled SpyGlace’s backdoor communications.
5. Bitbucket staged the next components
After its StatCounter activity, the downloader used an encoded victim identifier in a URL path to retrieve Service.dat from Bitbucket. That component then downloaded cbmp.txt and icon.txt from another Bitbucket repository.
Recommended Free Tools
The files were decoded and renamed:
cbmp.txtbecamecn.dat.icon.txtbecamesp.dat, the SpyGlace backdoor.
The reporting supports the conclusion that the attackers abused legitimate Bitbucket hosting and repositories. It does not show that Bitbucket’s core platform was breached.
Rank #3
This use of a reputable developer service makes simple domain blocking ineffective. Blocking all Bitbucket traffic could disrupt legitimate development, while allowing it without context gives attackers a permitted route for staging. Detection should combine destination, URI or repository path, process ancestry, file behavior, and payload characteristics.
Was WPS Office the initial access method?
The Hacker News reported that researchers linked the August 2024 activity to exploitation of CVE-2024-7262, described as a remote-code-execution vulnerability in WPS Office for Windows.
That attribution should be treated carefully. The infection path documented by JPCERT/CC prominently relied on phishing, a Google Drive-hosted VHDX, malicious LNK execution, and trusted-service abuse. The campaign should not be reduced to “a WPS Office exploit,” and the available reporting does not establish that every infection required CVE-2024-7262.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Organizations using WPS Office for Windows should apply the vendor’s security updates and verify whether affected versions were present. They should also investigate the broader delivery chain rather than looking only for evidence of the vulnerability.
Persistence through COM hijacking
APT-C-60 used COM hijacking to establish persistence. In a COM hijack, an attacker changes per-user COM registration so that a legitimate Windows component loads a malicious file when a particular COM object is invoked. Because the registration can be stored under a user profile, this technique may avoid the obvious signs associated with a startup-folder executable.
JPCERT/CC reported two relevant persistence stages:
Rank #4
| Component | Reported COM interface ID | Role |
|---|---|---|
SecureBootUEFI.dat |
F82B4EF1-93A9-4DDE-8015-F7950A1A6E31 |
Early persistent component |
cn.dat |
7849596a-48ea-486e-8937-a2a3009f31a9 |
Persistence and SpyGlace launch |
Reported file locations included:
%UserProfile%AppDataLocalMicrosoftWindowsShellService.dat%UserProfile%AppDataLocalMicrosoftWindowsFontscn.dat%UserProfile%AppDataLocalMicrosoftWindowsFontssp.dat
These paths are useful hunting leads, but filenames and locations can change in later variants. A clean search for one filename does not prove that a system is uncompromised.
What SpyGlace can do
SpyGlace is a full backdoor rather than a simple downloader. JPCERT/CC’s command table describes capabilities including:
- Listing directories.
- Deleting files and directories.
- Loading DLLs.
- Enumerating, creating, and terminating processes.
- Collecting disk information.
- Downloading encrypted and unencrypted files.
- Uploading files.
- Capturing screenshots and automatically uploading them.
- Providing remote command-shell access.
Those functions give an operator surveillance, collection, execution, and system-control capabilities. A compromised endpoint should therefore be treated as a potential credential, document, screenshot, and lateral-movement exposure—not merely as a machine that downloaded one suspicious file.
Indicators of compromise
The following indicators come from JPCERT/CC’s 2024 report. Keep them defanged and use them in controlled security tooling; do not visit the listed URLs.
Files and behavioral artifacts
| Indicator | Context |
|---|---|
Self-Introduction.lnk |
Shortcut inside the delivered VHDX |
IPML.txt |
Script or payload-stage filename |
SecureBootUEFI.dat |
Downloader and early persistence component |
Service.dat |
Bitbucket-retrieved second stage |
cn.dat |
COM-persistent launcher |
sp.dat |
SpyGlace backdoor |
905QD4656:H |
Observed SpyGlace mutex |
%AppData%MicrosoftVaultUserProfileRoaming |
Reported location for executed files with extensions including .exe, .dat, .db, and .ext |
Network indicators
103.6.244.46103.187.26.176c[.]statcounter[.]com/12959680/0/f1596509/1/c[.]statcounter[.]com/13025547/0/0a557459/1/bitbucket[.]org/hawnbzsd/hawnbzsd/downloadsbitbucket[.]org/hawnbzsd/hawnbzsd31/downloads
Reported Bitbucket artifacts included cbmp.txt, icon.txt, and rapd.txt. The reported C2 paths associated with 103.187.26.176 included:
Free tools Windows power users keep installed
One-click scans. No signup required.
POST /a78550e6101938c7f5e8bfb170db4db2/command.asp
POST /a78550e6101938c7f5e8bfb170db4db2/update.asp
POST /a78550e6101938c7f5e8bfb170db4db2/result.asp
POST /a78550e6101938c7f5e8bfb170db4db2/server.asp
GET /a78550e6101938c7f5e8bfb170db4db2/listen.asp
Decoding and initialization clues
For reverse-engineering and threat-hunting teams, JPCERT/CC reported these sample-specific details:
Best Value
- The StatCounter victim identifier used XOR 3 encoding.
Service.datused XOR keyg73qrc4dwx8jt9qmhi4s.cbmp.txtandicon.txtused Base64 and XOR keyAadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE.- The SpyGlace initialization included a connectivity check to
api[.]ipfy[.]org.
Validate these values against the specific sample before building automated detections; malware variants may change keys, filenames, and endpoints.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How defenders should hunt for APT-C-60 activity
Start with the delivery chain
- Search email, proxy, and endpoint telemetry for VHD or VHDX files delivered through recruiting, HR, or job-application messages.
- Identify recently mounted virtual disks and inspect them for LNK files, scripts, and decoy documents.
- Look for LNK execution spawning
git.exe, script interpreters,mshta.exe, or other living-off-the-land binaries. - Search user-writable locations for the reported filenames and unusual DAT files.
Inspect COM persistence
Search per-user COM registration for the two reported interface IDs and examine any associated DLL or file paths. Compare changes against software-installation records and known enterprise applications, because legitimate software can also modify COM registration.
Correlate the network sequence
The strongest network signal is not simply “StatCounter was contacted” or “Bitbucket was accessed.” Correlate:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors- A StatCounter connection from a non-browser process or suspicious script ancestry.
- A distinctive or encoded HTTP
Referer. - Subsequent Bitbucket raw or download-path access.
- Payload creation in the reported user-profile locations.
- Later traffic to the reported C2 infrastructure.
StatCounter traffic from normal browsers, Bitbucket use by developers, and legitimate git.exe activity can all be false positives when viewed alone.
Controls that reduce exposure
- Block or quarantine VHD and VHDX attachments and downloads where business use is not required.
- Treat LNK files inside archives and mounted disk images as high-risk.
- Restrict execution from user-writable locations where feasible.
- Patch WPS Office and assess exposure to CVE-2024-7262.
- Use application control or attack-surface-reduction policies to restrict unusual use of
git.exe,mshta.exe, PowerShell, and script interpreters. - Monitor cloud-storage downloads originating from recruiting or HR-themed messages.
- Inspect developer-platform and CDN traffic using process and URI context rather than blocking entire services by default.
- Retain sufficient endpoint telemetry to investigate LNK ancestry, mounted volumes, registry changes, and file writes.
What to do if compromise is suspected
- Isolate the endpoint without destroying evidence.
- Preserve the VHDX, LNK, scripts, payloads, registry hives, email, and endpoint telemetry.
- Capture volatile data if SpyGlace may still be active.
- Search for the reported COM identifiers, paths, mutex, hashes, domains, and C2 addresses.
- Hunt laterally for the same email, VHDX, filenames, and StatCounter-to-Bitbucket sequence.
- Rotate credentials used on the endpoint, prioritizing privileged and recruiting or HR accounts.
- Review access to documents, screenshots, credentials, and other sensitive data.
- Block or closely monitor the reported staging and C2 indicators.
- Reimage systems when persistence or payload removal cannot be verified confidently.
- Report confirmed activity to the relevant national CERT, sector ISAC, or incident-response provider.
APT-C-60 activity after 2024
The 2024 StatCounter and Bitbucket operation should not be conflated with every later APT-C-60 intrusion. In a 2026 report, JPCERT/CC described a newer pattern involving Proton Drive, RAR archives, LNK files containing JavaScript, mshta.exe, jsDelivr, GitHub, GitLab, and Codeberg. That reporting identified SpyGlace versions 3.1.15, 3.1.17, and 3.1.18, with no major functional differences noted compared with earlier versions.
The lesson is continuity of tradecraft, not identical infrastructure. APT-C-60 has continued combining phishing, containerized or archived delivery, Windows-native execution, legitimate online services, persistence, and SpyGlace deployment while changing services, accounts, paths, and versions.
Who is APT-C-60?
APT-C-60 is the designation used for this threat group. Researchers have associated it with South Korea-aligned cyber-espionage activity and apparent interest in East Asian targets, particularly Japan and South Korea. Reporting from Positive Technologies, Chuangyu 404 Lab, and others has also discussed similarities or possible links with APT-Q-12, also known as Pseudo Hunter, and the broader DarkHotel cluster.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Those relationships remain researcher assessments rather than publicly proven identities. It is more accurate to say that APT-C-60 has been linked or compared to those clusters than to state definitively that it is a DarkHotel subgroup.
The directly documented 2024 victim was an unnamed Japanese organization. Broader targeting conclusions should be treated as informed assessments based on related reporting and lure material, not as proof that every organization in the region was targeted.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

