Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Update on Attacks by Threat Group APT-C-60 in 2026

213.111.158.216

TLP:CLEAR
Active

IPv4 Address

Description

APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Update on Attacks by Threat Group APT-C-60 in 2026
Pattern Type
STIX
Confidence
75%
Valid From
Jul 14, 2026 02:00
Total Sightings
0
Added
Jul 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 213.111.158.216

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.