# APT-C-60

> As of 2026-09-07, APT-C-60 is a KR-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, apt. Also known as Zigzag Hail, APT-Q-12, Pseudo Hunter, DarkHotel cluster. ATT&CK coverage spans 49 techniques across 10 tactics in 5 of 5 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1140 (Deobfuscate/Decode Files or Information), T1027 (Obfuscated Files or Information).

- **Nation:** KR
- **Tracked threats:** 5
- **Categories:** MALWARE, APT
- **Also known as:** Zigzag Hail, APT-Q-12, Pseudo Hunter, DarkHotel cluster
- **As of:** 2026-09-07

## ATT&CK techniques observed

49 techniques observed across 5 of 5 tracked threats. Tactics: Stealth (formerly Defense Evasion) (13), Command and Control (10), Execution (6), Resource Development (6), Discovery (4), Initial Access (3).

- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 5 of 5 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 5 of 5 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 4 of 5 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 4 of 5 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 3 of 5 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 5 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 3 of 5 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 5 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 5 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 3 of 5 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 5 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 3 of 5 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 3 of 5 tracked threats
- [T1573.001](https://intel.threadlinqs.com/technique/T1573.001) Symmetric Cryptography — Command and Control — observed in 3 of 5 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 5 tracked threats

## Tracked threats

- [APT-C-60 Spear-Phishing Campaign Delivering SpyGlace via Proton Drive, RAR/LNK and Legitimate Developer Services](https://intel.threadlinqs.com/threat/TL-2026-2371) — HIGH
- [APT-C-60 Spear-Phishing Campaign Against Japanese Recruiters Using VHDX/LNK and SpyGlace Malware](https://intel.threadlinqs.com/threat/TL-2026-2134) — HIGH
- [SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr, Codeberg, Bitbucket) to Target Japan](https://intel.threadlinqs.com/threat/TL-2026-1284) — HIGH
- [APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services](https://intel.threadlinqs.com/threat/TL-2026-1249) — HIGH
- [APT-C-60 Spear-Phishing Campaign Deploying SpyGlace Spyware (v3.1.12-3.1.14) via VHDX/LNK and Git (gcmd.exe) LOLBin Abuse](https://intel.threadlinqs.com/threat/TL-2026-0777) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT-C-60
