Skip to main content
Mallory
Back to malware
MalwareUsed by 1 actor

Downloader2

Downloader2 is a second-stage downloader used in APT-C-60 campaigns observed by JPCERT/CC in Japan from June through August 2025. In the reported intrusion chain, spearphishing emails impersonating job applicants delivered a malicious VHDX to recruitment staff. Opening an embedded LNK executed a script via the legitimate Git component gcmd.exe, which dropped Downloader1. Downloader1 established persistence through COM hijacking, beaconed to StatCounter to identify victims, and retrieved a victim-specific tasking file from GitHub; based on the URL in that file, Downloader2 was downloaded and executed.

Downloader2’s documented role is to download and execute SpyGlace and its loader. It used an updated dynamic API resolution encoding scheme that applied add 0x04 followed by XOR 0x05, and it XOR-decoded retrieved content using the key string "AadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE". The retrieved payloads were executed via COM hijacking. The activity is associated with the threat group APT-C-60 and reflects the actor’s continued abuse of legitimate services, including GitHub for staged payload delivery. The content does not provide standalone hashes or other Downloader2-specific IoCs beyond its decoding key, execution via COM hijacking, and its role in delivering SpyGlace.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Darkhotel

“DownLoader1 then retrieves that file from GitHub… Based on the URL in the retrieved file, DownLoader2 is downloaded and executed… Downloader2 can download and execute SpyGlace and its loader.”

via jpcert blogblogs.jpcert.or.jp
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

「求職者を装い組織の採用担当に宛てた標的型攻撃メール…今回の攻撃では悪性のVHDXファイルが直接添付ファイルとして送られていました。」

Execution

3 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

「Gitによって実行されるスクリプトはデコイ文書の表示、ファイルの作成、実行を担い…」

T1204User ExecutionEvidence1
TacticExecution

「メールの受信者がVHDXファイル内に含まれているLNKファイルをクリックすることで…悪性のスクリプトが動作します。」

T1204.002Malicious FileEvidence1
TacticExecution

「VHDXファイル内に含まれているLNKファイルをクリック…」

Persistence

2 techniques
T1112Modify RegistryEvidence1

「…レジストリへ登録され… HKCU\Software\Classes\CLSID\{...}\InProcServer32」

T1546.015Component Object Model HijackingEvidence1

「…WebClassUser.dat…次に示すレジストリへ登録され、COMハイジャッキングによって永続化および実行」「HKCU\Software\Classes\CLSID\{566296fe-e0e8-475f-ba9c-a31ad31620b1}\InProcServer32」

T1546.015Component Object Model HijackingEvidence1

「…WebClassUser.dat…次に示すレジストリへ登録され、COMハイジャッキングによって永続化および実行」「HKCU\Software\Classes\CLSID\{566296fe-e0e8-475f-ba9c-a31ad31620b1}\InProcServer32」

Stealth

2 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

「取得したファイルは…XORデコード後に実行」「SpyGlaceは…BASE64とRC4…改変されたRC4」「AES128-CBCにて復号」

T1218System Binary Proxy ExecutionEvidence1
TacticStealth

「正規ファイルであるGit経由で悪性のスクリプトが動作… gcmd.exe(Gitの正規ファイル)が実行され… type glog.txt | gcmd.exe」

T1112Modify RegistryEvidence1

「…レジストリへ登録され… HKCU\Software\Classes\CLSID\{...}\InProcServer32」

T1102Web ServiceEvidence1

「攻撃者はペイロードの配布にGitHubを使用…」「Downloader1はstatcounterという正規の統計サービスに対して一定間隔で通信」

T1105Ingress Tool TransferEvidence1

「https://raw.githubusercontent.com/.../[VolumeSerialNumber + ComputerName].txt…その取得したファイルに記載されているURLを元に次のDownloader2のダウンロードおよび実行」

INDICATORS OF COMPROMISE

IOCs tracked for this family

3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Other
3 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in app7 months ago
uri●●●●●●●●●●●●View more in app7 months ago
uri●●●●●●●●●●●●View more in app7 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching3

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.