APT-C-60

☆ pin
Reports
3
First seen
Nov 5, 2025
Last seen
Jul 30, 2026
Motivation
Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Sectors
Victim regions
×2
×2
Japan×2

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×3T1204 User Execution ×3T1005 Data from Local System ×2T1218 System Binary Proxy Execution ×2T1546 Event Triggered Execution ×1T1003 OS Credential Dumping ×1T1027 Obfuscated Files or Information ×1T1082 System Information Discovery ×1T1547 Boot or Logon Autostart Execution ×1T1190 Exploit Public-Facing Application ×1T1071.001 Application Layer Protocol - Web Protocols ×1T1041 Exfiltration Over C2 Channel ×1

Indicators

hash_sha256 ×128filename ×24email ×13cve ×10ip_v4 ×7url ×6domain ×4hash_md5 ×3registry_key ×1

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.