SpyGlace is a custom Windows backdoor associated with the South Korea-aligned espionage group APT-C-60 and used in sustained cyberespionage campaigns targeting organizations in Japan and other East Asian victims. It has been observed as the final payload in multi-stage intrusion chains that rely on social engineering, abuse of legitimate cloud and developer services, and living-off-the-land execution techniques to reduce detection.
Observed delivery chains include spear-phishing emails impersonating job applicants, malicious archives containing shortcut files, and exploitation of WPS Office for Windows through CVE-2024-7262 and CVE-2024-7263. In phishing-led campaigns, victim interaction with a shortcut or document triggers staged downloaders and loaders that use trusted services for payload retrieval and tasking before deploying SpyGlace. Earlier campaigns also used virtual disk images and COM hijacking for persistence.
SpyGlace functions as an espionage backdoor with command execution and data theft capabilities. Reported behavior across versions includes downloading and decrypting additional payloads, loading auxiliary modules, executing exported functions from loaded modules, and exfiltrating victim data. Its command set evolved over time, with later versions adding module-unload functionality and modifying other commands. Communications with command-and-control infrastructure use layered obfuscation and encryption, including Base64 and an RC4-derived scheme, while the malware and its supporting components employ string and API obfuscation to complicate analysis.
Versions observed publicly include the 3.1.12 through 3.1.18 range. Builds seen in 2025 and 2026 were assessed as incremental updates rather than major redesigns, with changes such as mutex and autorun-path adjustments, refined tracking mechanisms, and modified encryption or obfuscation details. SpyGlace is notable less for destructive effects than for stealthy persistence within targeted environments and its integration into APT-C-60 tradecraft centered on long-term intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). APT-C-60, a South Korea-aligned cyberespionage group, was exploiting it to target East Asian countries. | The final payload in the APT-C-60 attack is a custom backdoor with cyberespionage capabilities that ESET Research internally named SpyGlace.
APT-C-60 ... orchestrating multi-stage campaigns to deploy the SpyGlace back-door... ultimately loading SpyGlace... executing sp.dat (SpyGlace) as the back-door.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ダウンローダーはこれらの正規サービスから最終的にSpyGlaceというマルウェアをダウンロードし、実行します。今回の攻撃ではSpyGlaceのv3.1.15、v3.1.17、v3.1.18を確認しています
20 distinct techniques documented for this family, organized by ATT&CK tactic.
感染時に使用されたLNKファイルは、実行されると自身をコピーした後、mshta.exeを使用して自身に含まれているJavaScriptを実行します。
ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). APT-C-60, a South Korea-aligned cyberespionage group, was exploiting it to target East Asian countries.
Since this is a one-click vulnerability, the exploit developers embedded a picture of the spreadsheet’s rows and columns inside to deceive and convince the user that the document is a regular spreadsheet. The malicious hyperlink was linked to the image so that clicking on a cell in the picture would trigger the exploit.
it contains a specially crafted and hidden hyperlink designed to trigger the execution of an arbitrary library if clicked... an attacker would need to store a malicious library somewhere accessible by the targeted computer either on the system or on a remote share, and know its file path in advance.
That code downloads a file named contributing1.txt, decodes it, and extracts its contents.
it contains a specially crafted and hidden hyperlink designed to trigger the execution of an arbitrary library if clicked... an attacker would need to store a malicious library somewhere accessible by the targeted computer either on the system or on a remote share, and know its file path in advance.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SpyGlace is a backdoor used in APT-C-60 campaigns against organizations in Japan. It enables operators to run commands and steal data from victim machines.
A malware payload delivered via spear-phishing and a staged infection chain using LNK files, mshta.exe, JavaScript, git.exe, and multiple downloader/loader stages. It uses trusted developer and content-delivery services for follow-on downloads and communicates with command-and-control infrastructure. JPCERT/CC observed versions 3.1.15, 3.1.17, and 3.1.18 with no major functional differences from earlier samples.
A malware payload delivered by multi-stage downloaders after spear-phishing, LNK execution, JavaScript via mshta.exe, and abuse of legitimate services such as GitHub, GitLab, jsDelivr, and Codeberg. It communicates with attacker-controlled C2 infrastructure and was observed in versions 3.1.15, 3.1.17, and 3.1.18.
APT-C-60 campaign malware delivered by staged downloaders via abused legitimate services such as GitHub, GitLab, jsDelivr, and Codeberg. It is the final payload executed on victim systems; observed versions were 3.1.15, 3.1.17, and 3.1.18.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.