{"id":8234,"date":"2025-11-06T10:05:07","date_gmt":"2025-11-06T10:05:07","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/06\/apt-c-60-attacking-job-seekers-to-download-weaponized-vhdx-file-from-google-drive-to-steal-sensitive-data\/"},"modified":"2025-11-06T10:05:07","modified_gmt":"2025-11-06T10:05:07","slug":"apt-c-60-attacking-job-seekers-to-download-weaponized-vhdx-file-from-google-drive-to-steal-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/06\/apt-c-60-attacking-job-seekers-to-download-weaponized-vhdx-file-from-google-drive-to-steal-sensitive-data\/","title":{"rendered":"APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data"},"content":{"rendered":"<p>    APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated espionage campaign targeting recruitment professionals has emerged, with the APT-C-60 threat group weaponizing VHDX files to compromise organizations.<\/p>\n<p>The threat actors impersonate job seekers in spear-phishing emails sent to recruitment staff, exploiting trust relationships to deliver malicious payloads.<\/p>\n<p>While earlier campaigns directed victims to download VHDX files from Google Drive, recent attacks have evolved to attach the malicious VHDX file directly to emails.<\/p>\n<p>Once a victim opens the weaponized VHDX file and clicks the embedded LNK file, a malicious script executes via Git, a legitimate application, initiating a multi-stage infection process that deploys sophisticated data-stealing malware.<\/p>\n<p>JPCERT analysts <a href=\"https:\/\/blogs.jpcert.or.jp\/en\/2025\/11\/APT-C-60_update.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign targeting East Asian regions, particularly Japan, between June and August 2025.<\/p>\n<p>The threat group demonstrates advanced operational security by leveraging legitimate services like GitHub and statcounter to maintain command-and-control infrastructure.<\/p>\n<p>The attacks showcase technical sophistication through multi-layered obfuscation techniques, including XOR encoding with the key \u201csgznqhtgnghvmzxponum\u201d for initial payloads and AES-128-CBC encryption for secondary stage downloads.<\/p>\n<p>The malware identifies compromised machines using volume serial numbers and computer names, enabling precise victim tracking.<\/p>\n<p>The infection chain begins when the LNK file executes gcmd.exe, a legitimate Git component, which runs the script glog.txt stored within the VHDX file.<\/p>\n<p>This script displays a fabricated resume as a decoy while simultaneously creating WebClassUser.dat (Downloader1) and registering it in the system registry at <code>HKCUSoftwareClassesCLSID{566296fe-e0e8-475f-ba9c-a31ad31620b1}InProcServer32<\/code>.<\/p>\n<p>Persistence is established through <a href=\"https:\/\/cybersecuritynews.com\/malware-com-hijacking-persistence\/\" target=\"_blank\" rel=\"noreferrer noopener\">COM hijacking<\/a>, ensuring the malware executes automatically during system operations.<\/p>\n<p>Downloader1 communicates with statcounter using specially crafted referrer headers in the format <code>ONLINE=&gt;[Number1],[Number2] &gt;&gt; [%userprofile%] \/ [VolumeSerialNumber + ComputerName]<\/code>.<\/p>\n<p>The threat actors monitor these referrer values and upload corresponding files to GitHub repositories. Downloader1 retrieves files from URLs like <code>https:\/\/raw.githubusercontent.com\/carolab989\/class2025\/refs\/heads\/main\/[VolumeSerialNumber+ComputerName].txt<\/code>, which contain instructions for downloading Downloader2.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-payload-deployment\"><strong>Infection Mechanism and Payload Deployment<\/strong><\/h2>\n<p>The infection mechanism employs a cascading deployment strategy with multiple encoded layers.<\/p>\n<p>Downloader2 downloads and deploys SpyGlace malware, utilizing dynamic API resolution with an encoding scheme combining ADD and XOR operations.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg2pD84EgtKEzk4Ly9_5CIL1B2dojDSOHobRwD6V8SkOyB1L_yCHL7UekHLnB4AzHAtRDvilWUUHAD7o6LIMvbu_f8Sz47S5TI6GnJA_BG9p1KCFr8XDbubZMvzcagFK5dPp1XlpSxtc84JmCyxJQQnQwu39K-1iKjWURcf0OximYQM_nuYp68KxVhN-9c\/s16000\/Flow%2520of%2520malware%2520infection%2520%28Source%2520-%2520JPCert%29.webp?ssl=1\" alt=\"Flow of malware infection (Source - JPCert)\"><figcaption class=\"wp-element-caption\">Flow of malware infection (Source \u2013 JPCert)<\/figcaption><\/figure>\n<\/div>\n<p>The current version applies XOR 0x05 after ADD 0x04, representing an evolution from earlier variants. Files retrieved by Downloader2 are XOR-decoded using the key \u201cAadDDRTaSPtyAG57er#$ad!lDKTOPLTEL78pE\u201d before execution through COM hijacking.<\/p>\n<p>SpyGlace versions 3.1.12 through 3.1.14 have been observed implementing comprehensive data exfiltration capabilities through 17 distinct commands.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> communicates with command-and-control servers at IP address 185.181.230.71 using modified RC4 encryption combined with BASE64 encoding.<\/p>\n<p>The modified RC4 implementation increases Key Scheduling Algorithm cycles and performs additional XOR operations.<\/p>\n<p>SpyGlace employs a characteristic encoding scheme combining single-byte XOR with SUB instructions for string obfuscation and API resolution.<\/p>\n<p>The download command retrieves encrypted files and decrypts them using AES-128-CBC with the hardcoded key <code>B0747C82C23359D1342B47A669796989<\/code> and IV <code>21A44712685A8BA42985783B67883999<\/code>, creating files at <code>%temp%wcts66889.tmp<\/code>.<\/p>\n<p>The malware establishes persistence by changing its automatic execution path from <code>%public%AccountPicturesDefault<\/code> in version 3.1.13 to <code>%appdata%MicrosoftSystemCertificatesMyCPLs<\/code> in version 3.1.14.<\/p>\n<p>SpyGlace implements comprehensive <a href=\"https:\/\/cybersecuritynews.com\/smarter-security-how-modern-surveillance-improves-business-decisions\/\" target=\"_blank\" rel=\"noreferrer noopener\">surveillance<\/a> capabilities, including remote shell access, file manipulation, process control, disk enumeration, and automated screenshot capture through the screenupload command, which calls the Clouds.db module at <code>%LocalAppData%MicrosoftWindowsCloudsClouds.db<\/code> with the export function mssc1.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apt-c-60-attacking-job-seekers\/\">APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apt-c-60-attacking-job-seekers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>APT-C-60 Attacking Job Seekers to Download Weaponized VHDX File from Google Drive to Steal Sensitive Data A sophisticated espionage campaign targeting recruitment professionals has emerged, with the APT-C-60 threat group weaponizing VHDX files to compromise organizations. The threat actors impersonate job seekers in spear-phishing emails sent to recruitment staff, exploiting trust relationships to deliver malicious [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8234","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8234"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8234"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8234\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}