Threadlinqs IntelligenceStart free

Threat actorKRTracked since 2026-06

APT-C-60

Also known as:Zigzag HailAPT-Q-12Pseudo HunterDarkHotel cluster

As of 2026-09-07, APT-C-60 is a KR-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, apt. Also known as Zigzag Hail, APT-Q-12, Pseudo Hunter, DarkHotel cluster. ATT&CK coverage spans 49 techniques across 10 tactics in 5 of 5 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1140 (Deobfuscate/Decode Files or Information), T1027 (Obfuscated Files or Information).

Tracked threats
55 high
First seen
2026-06-11
Last seen
2026-09-07
ATT&CK techniques
49across 5 of 5 threats
Related CVEs
0None referenced
Attribution
KRNation or origin
Nation: KR · 5 tracked threat(s) · Categories: MALWARE, APT

Activity timeline

APT-C-60 appears in 5 tracked threats between and ; the busiest month was 2026-07 with 2 reports.

ATT&CK techniques observed

49 techniques observed across 5 of 5 tracked threats · Stealth (formerly Defense Evasion) (13), Command and Control (10), Execution (6), Resource Development (6), Discovery (4), Initial Access (3)
  • T1082 System Information Discovery — Discoveryobserved in 5 of 5 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1113 Screen Capture — Collectionobserved in 4 of 5 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 5 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 5 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 3 of 5 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 3 of 5 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 5 tracked threats
  • T1102 Web Service — Command and Controlobserved in 3 of 5 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 5 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 5 tracked threats
  • T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 3 of 5 tracked threats
  • T1573.001 Symmetric Cryptography — Command and Controlobserved in 3 of 5 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 5 tracked threats

Tracked threats