216.73.217.22

Attacks by APT-C-60 Group Exploiting Legitimate Services

· Published 27/11/2024 18:36 · Modified 29/11/2024 13:34

Export JSON

Essential information

Published
27/11/2024 18:36
Modified
29/11/2024 13:34
Tags
2024-11-27 bitbucket com hijacking downloader east asia lnk phishing spygrace statcounter vhdx
Related entities
1 intrusion sets (apt), 19 techniques (mitre), 1 malware, 2 others

Description

The APT-C-60 group targeted organizations in Japan and with a sophisticated attack campaign. The attack begins with a email containing a Google Drive link to download a file. This file includes an file that executes a , which then retrieves a backdoor called . The attackers use legitimate services like and for command and control. The malware achieves persistence through and employs various techniques to evade detection. The campaign likely targeted multiple East Asian countries, using similar tactics across different attacks.

External references