Threat Intelligence / Actor / APT-C-60
APT-C-60
As of 2026-07-21, APT-C-60 is a South Korea (suspected origin/alignment)-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as Zigzag Hail, dark hotel, dubnium, egobot.
Also known as: APT-C-60, Zigzag Hail, dark hotel, dubnium, egobot, fallout team, nemim, paladin, purple pygmy, shadow crane, tapaoux, templar
Tracked threats
- SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr, Codeberg, Bitbucket) to Target Japan — HIGH
- APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services — HIGH
- APT-C-60 Spear-Phishing Campaign Deploying SpyGlace Spyware (v3.1.12-3.1.14) via VHDX/LNK and Git (gcmd.exe) LOLBin Abuse — HIGH
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →