SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr, Codeberg, Bitbucket) to Target Japan — Threadlinqs Intelligence
As of 2026-07-13, SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr, Codeberg, Bitbucket) to Target Japan is a high-severity malware threat attributed to APT-C-60 (South Korea (suspected origin/alignment)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 77 indicators of compromise.
Threat ID: TL-2026-1284 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: APT-C-60 · South Korea (suspected origin/alignment) · ESPIONAGE
APT-C-60 (aka Naikon), a South Korea-aligned cyber-espionage group active since 2021, is running a spear-phishing campaign against Japanese organizations that delivers the SpyGlace backdoor
APT-C-60 (also tracked as Naikon, and linked to the broader DarkHotel/APT-Q-12 cluster) has been conducting sustained cyber-espionage operations against Japanese organizations since at least 2021, with its custom SpyGlace backdoor observed in the wild as early as June 2022. The July 2026 campaign documented by JPCERT/CC and reported by Cyber Security News begins with spear-phishing emails containing Proton Drive links that deliver password-protected RAR archives. Inside each archive is a Windows shortcut (.lnk) file disguised as a document (e.g., desk.lnk, idx2.lnk, information.lnk, ipo6.lnk). When opened, the LNK invokes mshta.exe, Microsoft's signed HTML Application host, to execute an embedded, obfuscated JavaScript payload. This script retrieves an encoded text file (contributing[1].txt) staged on jsDelivr (a legitimate open-source CDN that mirrors GitHub content), decodes it, and uses it to marshal the legitimate git.exe binary into cloning or fetching further staged content from a network of throwaway GitHub, GitLab, and Codeberg repositories. Fragmented downloader components (TMI003.db through TMI400.db) are reassembled locally into a functional downloader (iconcache.dat, Cached2014.tmp, EncodedFile.tmp) which in turn retrieves and loads the SpyGlace backdoor DLL (ndsdll.dat, dll.tmp, jj.dll, sdll.tmp) into memory. Statcounter's legitimate web-analytics beacon (c.statcounter.com) is abused as a covert device-fingerprinting/check-in mechanism before the final payload is served, allowing operators to filter out sandboxes and non-target victims. This chain mirrors APT-C-60's historical tradecraft: earlier 2024 campaigns used a WPS Office zero-day (CVE-2024-7262) to drop SpyGlace as TaskControler.dll, later campaigns delivered VHDX virtual-disk containers with job-application lures (Self-Introduction.lnk) that install a SecureBootUEFI.dat downloader via COM hijacking (T1546.015) for persistence, using XOR-obfuscated C2 traffic to a Bitbucket-staged C2 (103.187.26.176) and StatCounter for device ID. The July 2026 wave keeps the git.exe/legitimate-platform abuse pattern but shifts distribution to GitHub/GitLab/jsDelivr/Codeberg rather than Bitbucket/Google Drive, and re-uses Proton Drive/Protonmail infrastructure for phishing delivery and operator communications (asako.t1011@protonmail.com, ayuko0328@protonmail.com senders; sapphire679@proton.me, sapphire689@proton.me, meimei91@protonmail.com, rapefo2905@outlook.com, jewexo9791@outlook.com, legDevMachine@protonmail.com commit-author emails on the attacker-controlled repos). SpyGlace itself is a modular reconnaissance/data-exfiltration backdoor; JPCERT/CC's ongoing tracking of the family (versions 3.1.6 in 2024 through 3.1.12-3.1.18 in 2025-2026) shows incremental command-set changes — the prockill and proclist commands were neutered in 3.1.12+ while a new uld (upload) command was added — consistent with continuous operational refinement rather than a rewrite. The malware supports file theft, plugin loading, and arbitrary command execution once implanted, and operators route C2 through 20+ disposable GitHub repos, 8+ GitLab repos, and 3+ Codeberg repos, rotating infrastructure to complicate takedown and network-signature-based blocking. JPCERT/CC recommends defenders shift from destination/domain-based blocking (ineffective against abuse of legitimate CDNs and code-hosting platforms) to behavioral detection: alerting on mshta.exe spawned from LNK/archive contexts, git.exe executing from user-writable/temp directories, and unusual outbound connections from office productivity or HR-adjacent hosts to code-hosting CDNs immediately following email attachment execution.
Target sectors: general business, human resources recruitment, government-adjacent enterprise, technology
Target regions: japan, south korea, china, East Asia
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 77 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1566.001, T1204.002, T1059.007, T1218.005, T1546.015, T1218.005, T1027, T1140, T1036.005