APT-C-60 is a South Korea-aligned cyber espionage threat actor associated with operations targeting Japan. The group has been linked to persistent espionage activity using malware including SpyGlace and an encrypted downloader referred to as RadialAgent. Reported tradecraft includes delivery through virtual hard disk image files and malicious shortcut files, along with the use of GitHub for tasking or command distribution. The actor’s observed operations are consistent with intelligence collection objectives rather than financially motivated intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT-C-60 is conducting persistent espionage operations targeting Japan using the new SpyGlace malware, which leverages VHDX LNK files and GitHub-based tasking for persistence.
South Korea-aligned cyber espionage group distributing RadialAgent malware via malicious VHDX files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.