SpyGlace is a custom Windows backdoor associated with the APT-C-60 espionage cluster and used in sustained cyberespionage campaigns targeting organizations in Japan and other East Asian victims. It has been observed as the final payload in multi-stage intrusion chains that rely heavily on legitimate services and living-off-the-land execution to reduce detection. Public reporting links SpyGlace deployments to spearphishing operations using job-application and similar lures, malicious shortcut files inside archives or virtual disk images, and exploitation of WPS Office for Windows through CVE-2024-7262 and CVE-2024-7263.
Observed delivery chains show APT-C-60 using spearphishing emails that either carry malicious attachments directly or direct victims to cloud-hosted archives. Infection sequences have included LNK-triggered execution through mshta.exe, abuse of legitimate Git tooling to run attacker scripts, staged downloaders assembled from fragmented components, and retrieval of later-stage payloads from trusted developer and CDN platforms. Earlier campaigns also used malicious VHDX containers and COM hijacking for persistence. In exploit-driven activity, a weaponized WPS Spreadsheet document used a crafted hyperlink and automatic remote library download behavior to achieve code execution and ultimately install SpyGlace.
SpyGlace functions as an espionage backdoor with command execution and data theft capabilities. Reported behavior includes receiving operator tasking, downloading and decrypting additional content, loading modules or plugins, unloading modules through a dedicated command, and exfiltrating victim data. Variants have used layered obfuscation for strings and API resolution, AES decryption for downloaded payloads, and command-and-control communications protected with Base64 and RC4-derived encryption. Multiple versions have been documented, including 3.1.12 through 3.1.18, with reporting indicating incremental changes such as command-set adjustments, mutex and autorun-path changes, and refined tracking or encryption rather than major architectural redesign.
APT-C-60 has repeatedly blended SpyGlace operations with legitimate online infrastructure, including cloud storage, analytics, source-code hosting, and content-delivery services, likely to make malicious traffic resemble normal enterprise activity. The malware and its surrounding delivery ecosystem are consistent with long-term intelligence collection rather than disruptive or financially motivated operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). APT-C-60, a South Korea-aligned cyberespionage group, was exploiting it to target East Asian countries. | The final payload in the APT-C-60 attack is a custom backdoor with cyberespionage capabilities that ESET Research internally named SpyGlace.
APT-C-60 ... orchestrating multi-stage campaigns to deploy the SpyGlace back-door... ultimately loading SpyGlace... executing sp.dat (SpyGlace) as the back-door.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Larva-25001 deployed SpyGlace through Proton Drive, malicious RAR and LNK files, and a chain involving mshta.Exe and git.Exe.
ダウンローダーはこれらの正規サービスから最終的にSpyGlaceというマルウェアをダウンロードし、実行します。今回の攻撃ではSpyGlaceのv3.1.15、v3.1.17、v3.1.18を確認しています
20 distinct techniques documented for this family, organized by ATT&CK tactic.
感染時に使用されたLNKファイルは、実行されると自身をコピーした後、mshta.exeを使用して自身に含まれているJavaScriptを実行します。
ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). APT-C-60, a South Korea-aligned cyberespionage group, was exploiting it to target East Asian countries.
Since this is a one-click vulnerability, the exploit developers embedded a picture of the spreadsheet’s rows and columns inside to deceive and convince the user that the document is a regular spreadsheet. The malicious hyperlink was linked to the image so that clicking on a cell in the picture would trigger the exploit.
it contains a specially crafted and hidden hyperlink designed to trigger the execution of an arbitrary library if clicked... an attacker would need to store a malicious library somewhere accessible by the targeted computer either on the system or on a remote share, and know its file path in advance.
That code downloads a file named contributing1.txt, decodes it, and extracts its contents.
it contains a specially crafted and hidden hyperlink designed to trigger the execution of an arbitrary library if clicked... an attacker would need to store a malicious library somewhere accessible by the targeted computer either on the system or on a remote share, and know its file path in advance.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered via Proton Drive, malicious archive and shortcut files, and an execution chain involving mshta.exe and git.exe.
SpyGlace is a backdoor used in APT-C-60 campaigns against organizations in Japan. It enables operators to run commands and steal data from victim machines.
A malware payload delivered via spear-phishing and a staged infection chain using LNK files, mshta.exe, JavaScript, git.exe, and multiple downloader/loader stages. It uses trusted developer and content-delivery services for follow-on downloads and communicates with command-and-control infrastructure. JPCERT/CC observed versions 3.1.15, 3.1.17, and 3.1.18 with no major functional differences from earlier samples.
A malware payload delivered by multi-stage downloaders after spear-phishing, LNK execution, JavaScript via mshta.exe, and abuse of legitimate services such as GitHub, GitLab, jsDelivr, and Codeberg. It communicates with attacker-controlled C2 infrastructure and was observed in versions 3.1.15, 3.1.17, and 3.1.18.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.