Dormant Medium impact Espionage Checked 5d ago

Spy group APT-C-60 keeps hitting Japanese organizations

A hacking group tracked as APT-C-60 is running an ongoing spying campaign against organizations in Japan. Japan's national CERT says the group now sends phishing emails with Proton Drive links that lead to a booby trapped shortcut file, which quietly installs spyware called SpyGlace. The group has used this kind of attack since at least late 2024 and updated its tools again in 2026.

Started
Jul 13, 2026
Latest activity
Jul 13, 2026
Attributed to
APT-C-60Suspected
Where
Japan
Sectors
Multiple sectors
Scale
multiple organizations in Japan, exact number not disclosed

Current status

Japan's JPCERT/CC said on July 13, 2026 that it is still seeing this group's phishing and malware activity, with new delivery tricks added this year; no newer confirmed activity has been reported since.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Security researchers have named the group APT-C-60 and some link it to South Korea, but no government has confirmed this publicly.

Impact

Victims who open the malicious files get infected with spyware that can let the attacker access and control their computer. No specific stolen data or business disruption has been made public.

What to do

Be wary of unexpected emails with cloud storage links or file attachments, especially shortcut (.lnk) files inside zip or rar archives, and verify with the sender before opening them.

Timeline

  1. Aug 8, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 13, 2026

    JPCERT/CC published details of new 2026 attacks by APT-C-60 using Proton Drive links and abusing GitHub, GitLab, jsDelivr and Codeberg to deliver SpyGlace malware.

    Activeblogs.jpcert.or.jp

Sources

Related reports