HomeSecurityAPT-C-60 impersonates job seekers

APT-C-60 impersonates job seekers

A sophisticated espionage campaign targeting recruitment professionals is being carried out by the APT-C-60 group, which uses malicious VHDX files to compromise organizations. The malicious actors impersonate job seekers in spear-phishing emails sent to recruitment staff, exploiting relationships of trust to deliver malicious payloads.

See also: Russian hackers target Ukrainian organizations with LotL strategies

APT-C-60
APT-C-60 impersonates job seekers

While previous campaigns directed victims to download VHDX files from Google Drive, recent attacks have evolved to attach the malicious VHDX file directly to emails. When a victim opens the malicious VHDX file and clicks on the embedded LNK file, a malicious script is executed via Git, a legitimate application, starting a multi-layered infection process that deploys sophisticated data-stealing malware.

JPCERT analysts have identified this campaign as targeting regions of East Asia, particularly Japan, between June and August 2025. The APT-C-60 group demonstrates advanced operational security by using legitimate services such as GitHub and statcounter to maintain its command and control infrastructure. The attacks demonstrate technical sophistication through multi-layered obfuscation techniques, including XOR encoding with the key “ sgznqhtgnghvmzxponum ” for initial payloads and AES-128-CBC encryption for secondary downloads.

The malware identifies compromised machines using volume serial numbers and computer names, allowing for precise tracking of victims. The infection chain begins when the LNK file executes gcmd.exe, a legitimate Git component, which executes the glog.txt script stored within the VHDX file. This script displays a fabricated resume as a deceptive one while simultaneously creating WebClassUser.dat (Downloader1) and registering it in the system registry. Persistent access is achieved through COM hijacking, ensuring that the malware is automatically executed during system operations.

See also: Prompt hijacking compromises MCP-based AI workflows

APT-C-60 impersonates job seekers
APT-C-60 impersonates job seekers

Downloader1 communicates with statcounter using specially crafted referral headers. Malicious actors track these referral values ​​and upload the corresponding files to GitHub repositories. Downloader1 retrieves files from specific URLs, which contain instructions to download Downloader2. The infection mechanism uses a deployment strategy with multiple encoded layers. Downloader2 downloads and deploys the SpyGlace, using dynamic API resolution with an encoding scheme that combines ADD and XOR operations.

The current version implements XOR 0x05 after ADD 0x04, representing an evolution from previous variants. Files retrieved by Downloader2 are decoded with XOR before execution via COM hijacking. SpyGlace versions 3.1.12 to 3.1.14 have been observed to implement extended data extraction capabilities via discrete commands. The modified RC4 implementation increases the Key Scheduling Algorithm cycles and performs additional XOR operations.

See also: Phishing: Hackers impersonate HR departments to steal Gmail credentials

Dream Job hacking SnailResin
APT-C-60 impersonates job seekers

SpyGlace uses a unique encoding scheme that combines single-byte XOR encoding with SUB commands for string obfuscation and API resolution. The get command retrieves encrypted files and decrypts them using AES-128-CBC with a hardcoded key, creating files in the temporary directory. The malware establishes persistent access by changing its auto-execution path in different versions. SpyGlace implements extensive monitoring capabilities, including remote shell access, file management, process control, disk enumeration, and automatic screenshot capture.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS