JPCERT Details APT-C-60 Attacks Using SpyGlace in 2026

· Original article ↗

Summary

JPCERT/CC describes APT-C-60 spear-phishing attacks using RAR-delivered LNK files, mshta.exe, and legitimate developer services to deploy SpyGlace, and publishes related IoCs.

Key points

  • Spear-phishing emails delivered a RAR archive through Proton Drive or included the malicious file as an attachment; opening its LNK file started the infection chain.
  • The LNK copied itself and used mshta.exe to run embedded JavaScript, which retrieved and extracted a file from jsDelivr and used git.exe to execute a script.
  • The script assembled a downloader from files in the extracted folder; subsequent downloaders and loaders retrieved and executed SpyGlace.
  • The attackers abused GitHub, GitLab, jsDelivr, and Codeberg as infrastructure, which may make malicious traffic harder to distinguish from normal activity.
  • JPCERT observed SpyGlace versions 3.1.15, 3.1.17, and 3.1.18, with no major functional differences from earlier versions identified.
  • JPCERT advises caution with suspicious email links and LNK files in archives; the article provides C2, file-hash, and other IoCs.

Article Details

Attack Vectors
  • Spear-phishing emails linked to Proton Drive to induce victims to download RAR archives containing malicious LNK files.
  • A similar observed case delivered the malicious file directly as an email attachment.
  • Opening the LNK file triggered mshta.exe to execute embedded JavaScript, which downloaded, decoded, and extracted additional files.
  • A legitimate git.exe executable ran a script that assembled a downloader from .db files. Additional downloaders, loaders, and SpyGlace were retrieved through abused legitimate services.
Defensive Notes
  • Avoid opening cloud storage links in suspicious emails or LNK files contained in archives such as RAR files.
  • Detection or blocking based solely on communication destinations is difficult because the attack abuses legitimate developer services and CDNs that are often allowed in corporate environments.
  • The infection chain abuses legitimate programs and standard Windows functionality, which the article notes can make detection difficult.

Indicators of compromise

TypeIndicatorContext
EMAILasako[.]t1011@protonmail[.]comSpear-phishing email sender identified in the attack.
EMAILayuko0328@protonmail[.]comSpear-phishing email sender identified in the attack.
EMAILjewexo9791@outlook[.]comEmail address listed as used for commits associated with the attacker repositories.
EMAILlegdevmachine@protonmail[.]comEmail address listed as used for commits associated with the attacker repositories.
EMAILmeimei91@protonmail[.]comEmail address listed as used for commits associated with the attacker repositories.
EMAILrapefo2905@outlook[.]comEmail address listed as used for commits associated with the attacker repositories.
EMAILsapphire679@proton[.]meEmail address listed as used for commits associated with the attacker repositories.
EMAILsapphire689@proton[.]meEmail address listed as used for commits associated with the attacker repositories.
IPV4154[.]18[.]239[.]209SpyGlace C2 server confirmed by JPCERT/CC.
IPV4173[.]234[.]11[.]141SpyGlace C2 server confirmed by JPCERT/CC.
IPV4185[.]18[.]222[.]241SpyGlace C2 server confirmed by JPCERT/CC.
IPV4213[.]111[.]158[.]200SpyGlace C2 server confirmed by JPCERT/CC.
IPV4213[.]111[.]158[.]201SpyGlace C2 server confirmed by JPCERT/CC.
IPV4213[.]111[.]158[.]216SpyGlace C2 server confirmed by JPCERT/CC.
IPV431[.]58[.]136[.]207SpyGlace C2 server confirmed by JPCERT/CC.
SHA256002e1207b96361fc4d53b10621225d61700003241fa38caacb411384b3d51135Downloader component: TMI400.db.
SHA2560120a6396952aec3f05ec0b0efe25e2a1b73545d55d74a3ac0bcd359d29f52bbDownloader component: TMI400.db.
SHA2560420fd9e5f9961458604909391fb0f1a353c17c986b55fc5722c1b68e41865dfMalicious Downloader2 artifact: item.tmp.
SHA2560bda4beded9c2923fe16f20b7cbd7baf1a5b7078be5cde715592529a974f9bd9Malicious Downloader2 artifact: Encoded_File.tmp.
SHA2560bf85d9065feb20ee946acf77c985cc7ec78de048ee41d8c5931e0e88873efaaAttack-chain JavaScript artifact: help.js.
SHA256119ad3dce05b5ef3db5a76655ac050eac51e318f1f31351ac103693a0a849158Malicious Downloader2 artifact: iconcache.dat.
SHA256131c27c3dce040979044ac1d363050c5d226af76aef1454bbf87c7193f8fc747Downloader component: TMI100.db.
SHA256131d8f72fde45c5ca1f662c510c3da16fbcd8ff6ef9b9fd893c25a9c8e8ec205Attack-chain JavaScript artifact: index.js.
SHA25614d799f7897d25f7cfb4d1c86f43c791b6d778d2efd92b5fac4f65fc472bf501Attack-chain JavaScript artifact: basecode.dat.
SHA256151b2dc70d141c12a33d8e45a80659fc53a71734e27233326bff150ac87744eaAttack-delivery RAR archive: 具体的内容.rar.
SHA25616bdde15cbf9190883c146bab495c8be73daff4fff5ffbf86b4ee46847103fbaAttack-chain JavaScript artifact: basecode.dat.
SHA25618683bba19695d325372d195634afd2f76b14896ba68225ba51ea5a039f2f76dDownloader component: TMI210.db.
SHA2561aaf59f05bb724d501cc9bcd6642ab8fd7347cf274d46c24719c9dced9b22beaDownloader component: TMI100.db.
SHA2561ae423e91f6cd679f9ea5be879b07379633b05cd850c37a8a65cdeaf508d097eAttack-chain JavaScript artifact: call41.js.
SHA2561b25c3d56fdb195b427a9c3bfc1f0e98e77a15322e8d3fc53a18edcc4891847fMalicious Downloader2 artifact: a101.dat.
SHA25621ddfbf726caa6d0f32a6bbce8e619f75c81f884bca48564c7a0e5a84bf4bd39Attack-chain JavaScript artifact: help.js.
SHA25622de84e8f29cba932cf65cf4dc1d333cb8b2e468204f97030712bee32691ac3bDownloader component: TMI100.db.
SHA25623b37d2ebe683cec3b145b6f2234ee728b99228cf3774399fcfad9502daab9a9Downloader component: TMI400.db.
SHA256248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbMalicious loader artifact: sdll2.tmp.
SHA2562952d72ad1d44f3d424600b8fa4076794e2e072ab46936012a5fb872c67ce189Malicious Downloader2 artifact: item.tmp.
SHA2562b650e2e2c46a52378aee70fbaff1ce5e832c759c5f937532047f52500428c4dMalicious loader artifact: Encoded_File.tmp.
SHA2562c98781e39a091b370ebd748b495c45752b2c54cdf2c36814358c8c6bd3ae912Attack-chain JavaScript artifact: help.js.
SHA2562d8def39b76ca17b419e5084832105c0167a171fdcc14eebd0c872ccb7bf9b0cMalicious LNK artifact: desk.lnk.
SHA2563b7a80fc62eb8b248fd0be0d94c78f1efe2f510499c68865a6d0c4ead6bc4055Attack-chain JavaScript artifact: help_v3.js.
SHA2563c509ec732979d8c91009d2c9f898bea81f3fc4064c3c56576257f61f9bfaaeeMalicious loader artifact: sdll3.tmp.
SHA2563e2bc0bd2eb84282086cc5946673b22414a16e982402f1f05ea57059d2962588Downloader component: TMI100.db.
SHA2563f2f69a8403e6b4e02ebe65448caf6abb8e2fbd1f7636ec71599f2d2d5fac8fbMalicious Downloader2 artifact: job.tmp or akdjfiwnkd.tmp.
SHA2563f67b777660241a1afc39f2ec388cac933a9eb31b3a34bddd12e39e663f1b566SpyGlace v3.1.18 artifact: test2.txt.
SHA25643d597783af656a35184021f5e20686896463a1712f9216e0217a2ca740e3935Downloader component: TMI100.db.
SHA25644a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fMalicious LNK artifact: ipo6.lnk.
SHA25645b2ba7c7a39817e1421f2abe2f869fa16af9651a6c863ac59683268fb391fe6Downloader component: TMI210.db.
SHA25648bb091e0cab562fe094e0ef6a77b434dba97380c09a707220cbd9ca37999484Malicious Downloader1 artifact: iconcache.dat.
SHA25650ebf107d522326c9a9db8821fe3263aa5136964faaf5dd183657bbb52725f84Downloader component: TMI100.db.
SHA2565115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dMalicious loader artifact: 0311_2nd_sdll.dat.
SHA2565272917261d7091a59e00f9d09cd7eb1d3e111115a5b367f79a66d0d7c7b01f4Attack-chain JavaScript artifact: help.js.
SHA256555360fb918b959176d669ef0ed40ec0b5ee57005fc625109891a16d02952462Downloader component: TMI320.db.
SHA25655640ad319208915593db8ad43724dddf6e6e17fc6b0014affa69c90f5cd1eb4Malicious loader artifact: sdll3.tmp.
SHA2565ab41cf20315d2ea1385967d588159873a65ef5581a0b78de06c0d8617894194Attack-chain JavaScript artifact: help_v5.js.
SHA2565c3d820e032592f47ffb4850ae0183749199b3e0dca3413cd0c3cb631e322f1bMalicious LNK artifact: 利権癒着の具体的内容.lnk.
SHA2565e97848bebf521766910d9c8378e98bf7aa1ce4b06aeb6c3f86c31ababbe9663Malicious Downloader1 artifact: iconcache.dat.
SHA25660972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5caMalicious Downloader1 artifact: iconcache.dat.
SHA25662a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525Attack-chain JavaScript artifact: help.dat.
SHA256669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304cSpyGlace v3.1.17 artifact: test2.txt.
SHA2566b84eab2aac7754b99d04365a83ec374e3cea99cc3223118a5f8fd545a8483e5Malicious Downloader2 artifact: Cached2014.tmp.
SHA2566cdc895eda4847f700d6f82fa2e3a8c72c10da1e16455985df855372142ebbd8Malicious loader artifact: test1.txt.
SHA25671819a1b856b49e7f194ce60468ed8e5ea925c75d01484f4d28ffcf69d480b36Malicious Downloader1 artifact: iconcache.dat.
SHA256771a47120b935e218322046e838347d722d265b91f1afdef91194a5bec86a97aDownloader component: TMI320.db.
SHA25678c108be692f1c45ed1da1988e3c5ac792c832a78d0b6e8e6550763156fe8f97Attack-chain JavaScript artifact: help.js.
SHA2567900c2772680523cadc9fe4e07300d45500191ba64ff5b91573531b133840b14Attack-chain JavaScript artifact: close.js.
SHA2567aa76237a7686583cc526b9d1a8486a52bd44a448d75ced51e1df4ba29ddb163Malicious installation script: msdic.log.
SHA2567b297f18ece81e87608e158288cc9c06cb9f4a8f1b2d2256aecf7bba8d7be2abDownloader component: TMI400.db.
SHA2567c3d0bebd263d3529132f2299de55a7801bf3ff40c833b13838be7a98ea3475eSpyGlace v3.1.18 artifact: test2.txt.
SHA2567d09891e26d56a8bec44c3fe9a5791f3a93e8fa31539951ae6e2c40af83ba42dAttack-chain JavaScript artifact: test.dat.
SHA2568114e3f213713dbbbacafcd0f62884a7826139b434bb3c77eae8dce656477621Attack-chain JavaScript artifact: call1.js.
SHA25683a22d4f61b054bda53a2ea4f506e97d818c7c961d8cd3975c1f2a51443cf95cMalicious Downloader1 artifact: iconcache.dat.
SHA256843c4dc402e96ed72d7716d980c99e5dfa222a2a322250b7c3755a00d142bc1fMalicious loader artifact: sdll.tmp.
SHA256866564bb455bb3c9f3e15cbbc1dcaf75c533a224eb96c4b6d6739e114ee1d065Malicious Downloader1 artifact: iconcache.dat.
SHA25686ab5161f761822d16637d4d34b84ca6e1f66cea905aa27510620c9cf5f170d8Malicious loader artifact: sDll_jj.dll.
SHA25686c49174a032ebbba6aeb1541e2aa84da0933b2eac3976f8705451c13bc7f325SpyGlace v3.1.18 artifact: test2.txt.
SHA256899ce01e7313f4c1cfcf07cb2456282ded1d6b6c57286762f2914a9d60de0146Malicious LNK artifact: idx2.lnk.
SHA2568a8cabe5f94e7f4c0ccca97f0c361618ec944df03d8b3bfcfdd76a25dd8f7a5aMalicious loader artifact: Encoded_File.tmp.
SHA2568ba3997afa07ac60312edf5f2d16357d1532a140081d638a9e4653768026ac56Malicious loader artifact: Encoded_File2.tmp.
SHA2568f08ead23767e1e4389927c40af167122b477ad17a98d388c863342dc9259c5eDownloader component: TMI400.db.
SHA2569394627e9c44cf2226ddf50012e5cf47ccf7d3bd8afa2395c635a93637e23502SpyGlace v3.1.15 artifact: sdll.tmp.
SHA25694072d60170fc72a528f68b2b3826638dbb7283c8906e8051f53fe16eaf054f8Attack-chain JavaScript artifact: close.js.
SHA2569706ee93f9b4b8214293e2ca4a68525eccaacfea58b135dcb2ea661a099ee9e6Attack-chain JavaScript artifact: help.js.
SHA2569789d80077998010c47a6a02ef1241eab11b69d667de8751b1e93fed6df913ebDownloader component: TMI400.db.
SHA2569a19598ea286d5f6fa0b7ff981ba21aff503fb217757f4dfbd496ead01805543Malicious loader artifact: sdll.tmp.
SHA256a18b5a78143f004f33aafad998b518ad9ee4dbdec44817a6e9b570e727d3e22cDownloader component: TMI400.db.
SHA256a1f0e6a30dc9753c5cbc80fd9df50eb44aee5a2349223b915b758af746275320Attack-chain JavaScript artifact: help.js.
SHA256a4c8a56070fe6f613e79a14554d0a1dba2f70ce2b93319e72972943cc66edf4aMalicious Downloader2 artifact: reaconinst.tmp.
SHA256a7981dfccd8e4bdc00133dc15b22472c1677d6270826863caa36e7d58ef50de0Malicious Downloader2 artifact: Encoded_File.tmp or inst.tmp.
SHA256a8bee6c4a5860b0ae08a984d2a6d62c13d3e91d9514262998924d2e0cef88f7cDownloader component: TMI400.db.
SHA256a9287e3452ab09144120ecdd20ed7365de589d5dcad28dcd8e191742d1ce5744Attack-chain JavaScript artifact: help_v4.js.
SHA256a9fd615fce38756ba6de8994f200e4b846397648138a9a0e6ef3b5952ef5e68cMalicious Downloader2 artifact: newjob.tmp.
SHA256ab5aba292c983db324987e9fde2e01fe24a979d1587888fcc7460c9489c54ee0Attack-chain JavaScript artifact: call2.js.
SHA256ad1c890f458b94683464c4d6d6d41fe63551c2c06ba2a1b8f71d8acb6ab16de3Attack-chain JavaScript artifact: close.js.
SHA256add013bf7ffc8a89789a7fd0ae0ff799c620af9b2755b214880b6a56768fd48cSpyGlace v3.1.15 artifact: sdll.tmp.
SHA256afca3bb9fb8d7a4ab4ceb9707f6d9a17352ccfb8ece83c68b01fbb419818e2fcDownloader component: TMI100.db.
SHA256b3f0d48506ff868ba145c9dcad7622bc37b723155648053ce2e2e73d8ea30e93SpyGlace v3.1.18 artifact: test2.txt.
SHA256b5458541732f91793ef89cc58ec5e46d04bf43985ab4e6dc5ad10b6da21581ecAttack-chain JavaScript artifact: call3.js.
SHA256c1faaff24d58af798c77d34405379df0a9e883e5bd1100a86d4c3e001414acd8Malicious loader artifact: sdll3.tmp.
SHA256c4768d99445128c670a6f848bc69371872e4d6a2160dbe0073e62ffd786c94eeMalicious Downloader2 artifact: wincfg.db or Cached.tmp.
SHA256c86f319f64d25f23ac29d9b53c9764f06a150634ee8e2d836424d460e5a99b52SpyGlace v3.1.15 artifact: sdll.tmp.
SHA256c9295c923da64738b93ff1827a39a5cb8f6c71eab060de416c8175a4a67da524SpyGlace v3.1.18 artifact: test2.txt.
SHA256cc2a6a3b4b771aba341293d2321e5f7b70cf517403fe44a58635b043e8868bdbMalicious Downloader1 artifact: iconcache.dat.
SHA256d14214e95c9d1ea850e508dfe27928494f2155a7597e4ea0bad9f70690abb397Downloader component: TMI003.db.
SHA256d567af55c97b7a595fcde5082e37a752718044230c16704e24efb43025bed0c2Malicious installation script: msdic.log.
SHA256deba513e2dc52a2931e61f5ac6d550a7938c1f7f63f661867c09d6141ee98560Downloader component: TMI100.db.
SHA256e5f2c7068ade7b87d24c3b94bc749c351d53609f5fcaa48dce06234beaa2444fSpyGlace v3.1.15 artifact: Encoded_File.tmp.
SHA256e6a414a53206e25d061a11e63c7d381ab0eb80cd3d174bd13551e2c36f8b5c04Attack-chain JavaScript artifact: call4.js.
SHA256e8514a2372172b4975f77bf69d5e8b7708cfa60157b064fcab13d7a62a99cc55Malicious loader artifact: sdll.tmp.
SHA256f0af281623b422c1d45e7006d78678762341288c05abcb62648ce55c6b63acb6Malicious loader artifact: Encoded_File.tmp or sta.tmp.
SHA256f50a01ae446adfcaaddffe215abd94b5643211e83d52acf5de540abf9fb26045Malicious loader artifact: sdll3.tmp.
SHA256fa53663bfb80e197483e1a1bf123b94fa869e2d7f42b5fdfbff2869589b65a05Malicious Downloader1 artifact: iconcache.dat.
SHA256fa98deb16bd72f2f77349c8c24de674a007a3d1ec8e88dd590791a57c08ab8f6Malicious LNK artifact: information.lnk.
SHA256fd0c7713520bd19c3e2566e93696532aa7da39a0c5ce1a797b67ce777b56d395Malicious LNK artifact: desk.lnk.
SHA256ffe5853d19be1acfe12bd681c7390d8fa88534a471020e6866a9e7c37d01fea2Attack-chain JavaScript artifact: close.js.
URLhxxps[:]//c[.]statcounter[.]com/13178005/0/7f3c2735/1/Specific legitimate-service resource listed as attacker-used infrastructure.
URLhxxps[:]//cdn[.]jsdelivr[.]net/gh/mei1990789/class125/Specific jsDelivr resource listed as attacker-used infrastructure in the payload retrieval chain.
URLhxxps[:]//codeberg[.]org/Hamilton385673/eff88e889w33456Attacker management repository identified by JPCERT/CC.
URLhxxps[:]//codeberg[.]org/meca922199/ertlokefgpokjper2359Attacker management repository identified by JPCERT/CC.
URLhxxps[:]//codeberg[.]org/ochi_ma992/3tv9239irfn83Attacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/bohihef411/tuikfwovebAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/cafes39636/ngwtaepesfAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/cefobe3574/kojyyvtkqoAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/fehijow850/uywcrcvlnbAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/gixop88415/glfhvhtzihAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/hexif45133/yedkatinrcAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/jewexo9791/archibkyofAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/kapap40675/fpqtzyofdlAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/lowege1212/izrtyshergAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/mei1990789/class125Attacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/rapefo2905/rncprjmauwAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/sapphire679/tblsesarol/Attacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/sapphire689/dnaluakxitAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/vogenoc114/qlofnsayvlAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/wanib11399/zjeqopmfitAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/waxiyes819/dymcdbqqenAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/williams250666/bluenote554Attacker management repository identified by JPCERT/CC.
URLhxxps[:]//github[.]com/yefixi3890/krbgqbmlhoAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/cafes39636/ngwtaepesfAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/kapap40675/fpqtzyofdlAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/lowege1212/eboralfotjAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/rapefo2905/yedkatinrcAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/sapphire689/dnaluakxitAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/vogenoc114/qlofnsayvlAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/waxiyes819/dymcdbqqenAttacker management repository identified by JPCERT/CC.
URLhxxps[:]//gitlab[.]com/yefixi3890/krbgqbmlhoAttacker management repository identified by JPCERT/CC.

MITRE ATT&CK

People

Threat Actors

Malware

Products

Countries

Related Articles