Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

APT-C-60’s August 2024 operation combined a recruitment-themed phishing email, a Google Drive-hosted VHDX disk image, a malicious Windows shortcut, and trusted online services to deploy the SpyGlace backdoor against an unnamed Japanese organization. StatCounter helped the attackers identify victims, while Bitbucket staged additional malware components. The campaign was not simply a WPS Office exploit: its success depended on social engineering, user execution, Windows-native tools, COM hijacking, and abuse of legitimate cloud and developer platforms.

This article describes the 2024 campaign and separates it from related APT-C-60 activity reported in 2025 and 2026.

What happened in the APT-C-60 campaign?

According to JPCERT/CC’s analysis, a recruiting contact at an unnamed Japanese organization received an email that appeared to come from a prospective employee. The message directed the recipient to a file hosted on Google Drive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The download was a VHDX virtual-disk image. After it was mounted, the image exposed a decoy document and a shortcut named Self-Introduction.lnk. The shortcut used the legitimate git.exe executable to launch the next stage while opening the decoy document, helping the activity appear routine to the victim.

The resulting chain was:

Recruitment-themed email
        ↓
Google Drive-hosted VHDX
        ↓
Self-Introduction.lnk + decoy document
        ↓
git.exe launches script activity
        ↓
SecureBootUEFI.dat
        ↓
StatCounter victim identification
        ↓
Bitbucket retrieves Service.dat
        ↓
cbmp.txt and icon.txt become cn.dat and sp.dat
        ↓
COM hijacking persistence
        ↓
SpyGlace backdoor

JPCERT/CC identified the analyzed backdoor as SpyGlace, sample version 3.1.6. Earlier coverage used the spelling “SpyGrace”; JPCERT/CC corrected the name in a September 1, 2025 update.

How the infection chain worked

1. A convincing job-application lure

The attacker’s choice of a recruiting scenario was important. A recipient involved in hiring may reasonably expect unsolicited résumés, self-introductions, portfolios, or other documents from applicants. That context reduced the suspicion normally associated with an unexpected executable.

The decoy document served a second purpose: it gave the user something plausible to see after opening the shortcut while the malicious stages ran in the background.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. A VHDX file concealed the shortcut

A VHDX file is a virtual hard-disk image, not inherently a malware format. It can be used legitimately for virtual machines, software deployment, and testing. In this case, however, the image acted as a container for the malicious LNK file and decoy content.

Disk images can complicate email and endpoint inspection because the dangerous shortcut is inside the mounted volume rather than presented directly as the initial attachment. Organizations that allow VHD or VHDX use should still treat disk images delivered through unsolicited email or unfamiliar cloud-storage links as high-risk.

3. The LNK launched trusted Windows activity

Self-Introduction.lnk initiated script and payload activity through the legitimate git.exe executable. The chain also involved a file identified as IPML.txt, which created the downloader and decoy activity.

This is a classic detection challenge: the presence of git.exe is not suspicious by itself. Developers may use it every day. The stronger signal is the combination of a mounted VHDX, an LNK, unusual parent-child relationships, script execution, and subsequent connections to StatCounter and Bitbucket.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. SecureBootUEFI.dat contacted StatCounter

The downloader, saved as SecureBootUEFI.dat, contacted StatCounter before retrieving the next stage. JPCERT/CC reported that it placed a victim-specific string in the HTTP Referer header.

The value incorporated the computer name, the home directory, and a value derived from the computer name and username. Nonalphabetic characters were removed, and the result was encoded using XOR 3. This gave the attackers a way to distinguish individual infected systems.

StatCounter therefore played a victim-identification or signaling role in the reported chain. Calling it the complete command-and-control channel would be misleading. Bitbucket staged additional payloads, while separate infrastructure handled SpyGlace’s backdoor communications.

5. Bitbucket staged the next components

After its StatCounter activity, the downloader used an encoded victim identifier in a URL path to retrieve Service.dat from Bitbucket. That component then downloaded cbmp.txt and icon.txt from another Bitbucket repository.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The files were decoded and renamed:

  • cbmp.txt became cn.dat.
  • icon.txt became sp.dat, the SpyGlace backdoor.

The reporting supports the conclusion that the attackers abused legitimate Bitbucket hosting and repositories. It does not show that Bitbucket’s core platform was breached.

This use of a reputable developer service makes simple domain blocking ineffective. Blocking all Bitbucket traffic could disrupt legitimate development, while allowing it without context gives attackers a permitted route for staging. Detection should combine destination, URI or repository path, process ancestry, file behavior, and payload characteristics.

Was WPS Office the initial access method?

The Hacker News reported that researchers linked the August 2024 activity to exploitation of CVE-2024-7262, described as a remote-code-execution vulnerability in WPS Office for Windows.

That attribution should be treated carefully. The infection path documented by JPCERT/CC prominently relied on phishing, a Google Drive-hosted VHDX, malicious LNK execution, and trusted-service abuse. The campaign should not be reduced to “a WPS Office exploit,” and the available reporting does not establish that every infection required CVE-2024-7262.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizations using WPS Office for Windows should apply the vendor’s security updates and verify whether affected versions were present. They should also investigate the broader delivery chain rather than looking only for evidence of the vulnerability.

Persistence through COM hijacking

APT-C-60 used COM hijacking to establish persistence. In a COM hijack, an attacker changes per-user COM registration so that a legitimate Windows component loads a malicious file when a particular COM object is invoked. Because the registration can be stored under a user profile, this technique may avoid the obvious signs associated with a startup-folder executable.

JPCERT/CC reported two relevant persistence stages:

Component Reported COM interface ID Role
SecureBootUEFI.dat F82B4EF1-93A9-4DDE-8015-F7950A1A6E31 Early persistent component
cn.dat 7849596a-48ea-486e-8937-a2a3009f31a9 Persistence and SpyGlace launch

Reported file locations included:

  • %UserProfile%AppDataLocalMicrosoftWindowsShellService.dat
  • %UserProfile%AppDataLocalMicrosoftWindowsFontscn.dat
  • %UserProfile%AppDataLocalMicrosoftWindowsFontssp.dat

These paths are useful hunting leads, but filenames and locations can change in later variants. A clean search for one filename does not prove that a system is uncompromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What SpyGlace can do

SpyGlace is a full backdoor rather than a simple downloader. JPCERT/CC’s command table describes capabilities including:

  • Listing directories.
  • Deleting files and directories.
  • Loading DLLs.
  • Enumerating, creating, and terminating processes.
  • Collecting disk information.
  • Downloading encrypted and unencrypted files.
  • Uploading files.
  • Capturing screenshots and automatically uploading them.
  • Providing remote command-shell access.

Those functions give an operator surveillance, collection, execution, and system-control capabilities. A compromised endpoint should therefore be treated as a potential credential, document, screenshot, and lateral-movement exposure—not merely as a machine that downloaded one suspicious file.

Indicators of compromise

The following indicators come from JPCERT/CC’s 2024 report. Keep them defanged and use them in controlled security tooling; do not visit the listed URLs.

Files and behavioral artifacts

Indicator Context
Self-Introduction.lnk Shortcut inside the delivered VHDX
IPML.txt Script or payload-stage filename
SecureBootUEFI.dat Downloader and early persistence component
Service.dat Bitbucket-retrieved second stage
cn.dat COM-persistent launcher
sp.dat SpyGlace backdoor
905QD4656:H Observed SpyGlace mutex
%AppData%MicrosoftVaultUserProfileRoaming Reported location for executed files with extensions including .exe, .dat, .db, and .ext

Network indicators

  • 103.6.244.46
  • 103.187.26.176
  • c[.]statcounter[.]com/12959680/0/f1596509/1/
  • c[.]statcounter[.]com/13025547/0/0a557459/1/
  • bitbucket[.]org/hawnbzsd/hawnbzsd/downloads
  • bitbucket[.]org/hawnbzsd/hawnbzsd31/downloads

Reported Bitbucket artifacts included cbmp.txt, icon.txt, and rapd.txt. The reported C2 paths associated with 103.187.26.176 included:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
POST /a78550e6101938c7f5e8bfb170db4db2/command.asp
POST /a78550e6101938c7f5e8bfb170db4db2/update.asp
POST /a78550e6101938c7f5e8bfb170db4db2/result.asp
POST /a78550e6101938c7f5e8bfb170db4db2/server.asp
GET  /a78550e6101938c7f5e8bfb170db4db2/listen.asp

Decoding and initialization clues

For reverse-engineering and threat-hunting teams, JPCERT/CC reported these sample-specific details:

  • The StatCounter victim identifier used XOR 3 encoding.
  • Service.dat used XOR key g73qrc4dwx8jt9qmhi4s.
  • cbmp.txt and icon.txt used Base64 and XOR key AadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE.
  • The SpyGlace initialization included a connectivity check to api[.]ipfy[.]org.

Validate these values against the specific sample before building automated detections; malware variants may change keys, filenames, and endpoints.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How defenders should hunt for APT-C-60 activity

Start with the delivery chain

  1. Search email, proxy, and endpoint telemetry for VHD or VHDX files delivered through recruiting, HR, or job-application messages.
  2. Identify recently mounted virtual disks and inspect them for LNK files, scripts, and decoy documents.
  3. Look for LNK execution spawning git.exe, script interpreters, mshta.exe, or other living-off-the-land binaries.
  4. Search user-writable locations for the reported filenames and unusual DAT files.

Inspect COM persistence

Search per-user COM registration for the two reported interface IDs and examine any associated DLL or file paths. Compare changes against software-installation records and known enterprise applications, because legitimate software can also modify COM registration.

Correlate the network sequence

The strongest network signal is not simply “StatCounter was contacted” or “Bitbucket was accessed.” Correlate:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. A StatCounter connection from a non-browser process or suspicious script ancestry.
  2. A distinctive or encoded HTTP Referer.
  3. Subsequent Bitbucket raw or download-path access.
  4. Payload creation in the reported user-profile locations.
  5. Later traffic to the reported C2 infrastructure.

StatCounter traffic from normal browsers, Bitbucket use by developers, and legitimate git.exe activity can all be false positives when viewed alone.

Controls that reduce exposure

  • Block or quarantine VHD and VHDX attachments and downloads where business use is not required.
  • Treat LNK files inside archives and mounted disk images as high-risk.
  • Restrict execution from user-writable locations where feasible.
  • Patch WPS Office and assess exposure to CVE-2024-7262.
  • Use application control or attack-surface-reduction policies to restrict unusual use of git.exe, mshta.exe, PowerShell, and script interpreters.
  • Monitor cloud-storage downloads originating from recruiting or HR-themed messages.
  • Inspect developer-platform and CDN traffic using process and URI context rather than blocking entire services by default.
  • Retain sufficient endpoint telemetry to investigate LNK ancestry, mounted volumes, registry changes, and file writes.

What to do if compromise is suspected

  1. Isolate the endpoint without destroying evidence.
  2. Preserve the VHDX, LNK, scripts, payloads, registry hives, email, and endpoint telemetry.
  3. Capture volatile data if SpyGlace may still be active.
  4. Search for the reported COM identifiers, paths, mutex, hashes, domains, and C2 addresses.
  5. Hunt laterally for the same email, VHDX, filenames, and StatCounter-to-Bitbucket sequence.
  6. Rotate credentials used on the endpoint, prioritizing privileged and recruiting or HR accounts.
  7. Review access to documents, screenshots, credentials, and other sensitive data.
  8. Block or closely monitor the reported staging and C2 indicators.
  9. Reimage systems when persistence or payload removal cannot be verified confidently.
  10. Report confirmed activity to the relevant national CERT, sector ISAC, or incident-response provider.

APT-C-60 activity after 2024

The 2024 StatCounter and Bitbucket operation should not be conflated with every later APT-C-60 intrusion. In a 2026 report, JPCERT/CC described a newer pattern involving Proton Drive, RAR archives, LNK files containing JavaScript, mshta.exe, jsDelivr, GitHub, GitLab, and Codeberg. That reporting identified SpyGlace versions 3.1.15, 3.1.17, and 3.1.18, with no major functional differences noted compared with earlier versions.

The lesson is continuity of tradecraft, not identical infrastructure. APT-C-60 has continued combining phishing, containerized or archived delivery, Windows-native execution, legitimate online services, persistence, and SpyGlace deployment while changing services, accounts, paths, and versions.

Who is APT-C-60?

APT-C-60 is the designation used for this threat group. Researchers have associated it with South Korea-aligned cyber-espionage activity and apparent interest in East Asian targets, particularly Japan and South Korea. Reporting from Positive Technologies, Chuangyu 404 Lab, and others has also discussed similarities or possible links with APT-Q-12, also known as Pseudo Hunter, and the broader DarkHotel cluster.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those relationships remain researcher assessments rather than publicly proven identities. It is more accurate to say that APT-C-60 has been linked or compared to those clusters than to state definitively that it is a DarkHotel subgroup.

The directly documented 2024 victim was an unnamed Japanese organization. Broader targeting conclusions should be treated as informed assessments based on related reporting and lure material, not as proof that every organization in the region was targeted.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.