Threat Intelligence / Actor / APT-C-60

APT-C-60

As of 2026-07-27, APT-C-60 is a South Korea (suspected origin/alignment)-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as Zigzag Hail, dark hotel, dubnium, egobot.

Nation: South Korea (suspected origin/alignment) · 3 tracked threat(s) · Categories: MALWARE

Also known as: APT-C-60, Zigzag Hail, dark hotel, dubnium, egobot, fallout team, nemim, paladin, purple pygmy, shadow crane, tapaoux, templar

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence