logo

017

ID: 8b3fc0c2-0f90-4843-ae56-6dcc5eb01cda

STIX ID: report--8b3fc0c2-0f90-4843-ae56-6dcc5eb01cda

Threat Score

85/100

Uploaded: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
APT-C-60 conducted a targeted espionage campaign in August 2024 against a Japanese organization using a job-application lure. The attackers delivered a VHDX-hosted payload that exploited WPS Office RCE (CVE-2024-7262) to run a downloader (SecureBootUEFI.dat) which used StatCounter and Bitbucket to retrieve and assemble the SpyGlace backdoor; persistence was achieved via COM hijacking and the backdoor contacted C2 at 103.187.26.176.