SpyGlace is a Windows backdoor associated with the espionage activity cluster tracked as APT-C-60 and used in sustained campaigns targeting organizations in Japan. It has been deployed through multi-stage spearphishing operations that impersonate job applicants or otherwise entice users to open malicious archives, virtual disk images, or shortcut files. Observed delivery chains use living-off-the-land and trusted-service abuse, including execution through legitimate Git tooling, script launch via mshta.exe, and staging or tasking through widely used cloud, developer, and CDN platforms such as GitHub, GitLab, Codeberg, StatCounter, and jsDelivr.
The malware is typically the final payload of a staged intrusion chain involving one or more downloaders and loaders. Earlier observed campaigns used malicious VHDX containers with embedded LNK files, while later campaigns used spearphishing emails carrying direct attachments or links to archives containing booby-trapped LNK files. Opening the shortcut initiates script execution, reconstructs downloader components, and ultimately installs SpyGlace. Persistence in related APT-C-60 operations has been achieved through COM hijacking, and the broader intrusion chain repeatedly reuses legitimate binaries and normal Windows functionality to reduce detection opportunities.
SpyGlace provides core backdoor functionality for remote command execution and data theft. Public reporting also attributes plugin or module loading behavior to the malware, including commands that invoke functions from loaded modules and unload them afterward. Across observed versions, SpyGlace uses layered obfuscation and encrypted communications, including Base64 with a modified RC4-like scheme for command-and-control traffic; some download functionality has also been documented using AES decryption for retrieved payloads. Reported version progression includes builds from the 3.1.12 through 3.1.18 range, with incremental changes to command handling, mutexes, autorun locations, and tracking or encryption details, but no major shift away from its established espionage-oriented backdoor role.
SpyGlace has primarily been observed in targeted intrusions against Japanese organizations, including recruitment and enterprise environments, where the operators rely on social engineering, trusted online services, and stealthy staging infrastructure to blend malicious activity with ordinary user and developer-platform traffic.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Public reporting indicates the group exploited a remote code execution vulnerability in the Windows version of a productivity suite (CVE-2024-7262) to drop SpyGlace.
APT-C-60 ... orchestrating multi-stage campaigns to deploy the SpyGlace back-door... ultimately loading SpyGlace... executing sp.dat (SpyGlace) as the back-door.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Next, the script uses a legitimate copy of git.exe from the extracted files to run another script. | The attack starts when a recipient opens the LNK file. The shortcut copies itself and launches mshta.exe, a legitimate Windows component, to run hidden JavaScript stored inside the file.
Although the JavaScript code embedded in the LNK file is obfuscated
That code downloads a file named contributing1.txt, decodes it, and extracts its contents.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SpyGlace is a backdoor used in APT-C-60 campaigns against organizations in Japan. It enables operators to run commands and steal data from victim machines.
A malware payload delivered via spear-phishing and a staged infection chain using LNK files, mshta.exe, JavaScript, git.exe, and multiple downloader/loader stages. It uses trusted developer and content-delivery services for follow-on downloads and communicates with command-and-control infrastructure. JPCERT/CC observed versions 3.1.15, 3.1.17, and 3.1.18 with no major functional differences from earlier samples.
A malware payload delivered by multi-stage downloaders after spear-phishing, LNK execution, JavaScript via mshta.exe, and abuse of legitimate services such as GitHub, GitLab, jsDelivr, and Codeberg. It communicates with attacker-controlled C2 infrastructure and was observed in versions 3.1.15, 3.1.17, and 3.1.18.
SpyGlace is the final malware payload delivered in the APT-C-60 intrusion chain. It is downloaded and executed by intermediate downloaders/loaders retrieved from abused legitimate services such as GitHub, GitLab, jsDelivr, and Codeberg, and the appendix identifies dedicated SpyGlace C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.