SAMURAI CYBER WATCH
Issue #12 — July 17, 2026
Practical Cyber Intelligence for Business Leaders in Non-Superpower Nations
THIS WEEK'S BRIEFING
APT-C-60 Targets Japan Through Trusted Cloud Platforms — and the Largest Patch Tuesday on Record Demands Immediate Action
JPCERT/CC confirms an active spear-phishing campaign abusing Proton Drive, GitHub, and GitLab as malware delivery channels. Microsoft's July 2026 Patch Tuesday covers 621 fixes including actively exploited zero-days. An AI-powered botnet that migrates its C2 infrastructure in six minutes. This week's incidents signal a clear shift: the attack surface is everywhere, and the window to respond is narrowing.
THE KEY DEVELOPMENT
APT-C-60 CONTINUES TO INFILTRATE JAPANESE ORGANIZATIONS USING LEGITIMATE CLOUD SERVICES AS COVER
On July 13, 2026, JPCERT/CC officially confirmed a new spear-phishing campaign attributed to APT-C-60. This group's multi-year targeting of Japan is well-documented, and the 2026 campaign represents a clear evolution in how the threat actors design their attack infrastructure.
The most significant aspect of this campaign is the deliberate use of legitimate cloud platforms as malware distribution channels — specifically Proton Drive, GitHub, GitLab, jsDelivr, and Codeberg. These are platforms that developers and enterprises use and trust daily. Because the domains hosting the malicious content already appear on allowlists, conventional URL filtering and proxy controls are structurally ill-suited to detect them. The malware being distributed is SpyGlace, with versions ranging from v3.1.15 to v3.1.18. The steady version increments confirm that active development of this malware is ongoing.
Also confirmed is the abuse of mshta.exe, the Windows-native Microsoft HTML Application Host binary, to execute JavaScript. This is a Living off the Land, or LotL, technique. Rather than introducing external malicious binaries, the attackers use legitimate OS-native tools as execution intermediaries, allowing them to evade behavioral detection by endpoint security products. JPCERT/CC's disclosure identified more than 24 compromised endpoints, confirming that this campaign is already operating at a scale that demands serious attention.
The initial access vector is spear-phishing email disguised as recruitment correspondence. HR and talent acquisition staff are structurally required to open external attachments and follow external links as a normal part of their job. Attackers are deliberately exploiting that structural vulnerability. Specific defensive measures addressing this exposure are outlined in the Defend Without Choosing Sides section below.
JAPAN LENS: THE "JAPAN IS NOT A TARGET" MYTH, AND TWENTY YEARS OF EVIDENCE TO THE CONTRARY
When I entered this industry in the early 2000s, a widespread belief existed within Japan that cyberattacks were primarily an American or European problem and that Japan was unlikely to be targeted. The following two decades have repeatedly and conclusively demonstrated how unfounded that optimism was.
The latest APT-C-60 campaign is yet another confirmation that Japan is an explicit, sustained, and deliberately chosen target. Analysis from multiple security organizations characterizes this group as a persistent threat actor based in East Asia. Their sustained interest in specific Japanese organizations is not incidental. It is the outcome of strategic, deliberate selection.
Placing this week's other incidents alongside that campaign makes the threat landscape facing Japanese organizations sharper and more coherent. The ransomware attack on Kaneko Agricultural Machinery demonstrates that manufacturing, a cornerstone of the Japanese economy, is already within the crosshairs. The zero-day vulnerabilities in the SonicWall SMA1000 series strike directly at the remote access devices that Japanese enterprises adopted broadly alongside the expansion of remote work. Attacks targeting the KNX protocol cast a shadow over the physical infrastructure of Japanese companies that have invested heavily in smart building technology and factory automation.
The language barrier and the cultural tendency toward caution in disclosing incidents can structurally slow the pace of information sharing. JPCERT/CC's relatively prompt public disclosure in this case is commendable. That said, in my experience, the interval that matters most is not when information is published but how long it takes an organization to translate that information into actual defensive action. The gap between receiving intelligence and acting on it is the window attackers exploit most effectively. Closing that gap is, right now, the most important challenge any organization can address.
BEYOND THE EPICENTER: WHY ORGANIZATIONS THAT ARE NEITHER NATION-STATES NOR LARGE ENTERPRISES SHOULD BE MOST ALERT THIS WEEK
Looking across this week's incidents, it may appear that the headlines are dominated by sophisticated attacks against large enterprises and government institutions. But I want to speak directly to small and mid-sized business owners and IT administrators: this week's content deserves your full attention.
Consider the critical vulnerability in nginx. Nginx is widely deployed as a cost-effective, high-performance web server across small and mid-sized e-commerce sites and business systems. Large enterprises have dedicated infrastructure teams. Smaller organizations often rely on outsourced vendors or part-time staff for server management, which means patches are applied more slowly. The moment a patch is published, it also signals to attackers that a window exists to scan for unpatched systems. That asymmetry is worth keeping in mind.
The critical vulnerability in Firefox already has publicly available exploit code. Browsers are used by every employee regardless of industry, and any organization that leaves updates to individual users' discretion is carrying real, present risk right now.
The same urgency applies to Microsoft's July 2026 Patch Tuesday release. This month's update is the largest on record, covering 621 fixes, and includes zero-day vulnerabilities that have already been confirmed exploited in the wild. The assumption that last month's patches are sufficient does not hold this month.
And as the Patriot Bait AI-powered botnet case illustrates, attack automation and speed are advancing on a clear trajectory. According to Trend Micro's analysis, this botnet uses AI to migrate its command-and-control infrastructure in as little as six minutes. The assumption that a small organization is too small to be worth targeting no longer has an objective basis.
STATE ACTOR WATCH: INDICATORS OF STATE INVOLVEMENT OBSERVED THIS WEEK
Several of this week's incidents contain elements suggesting the involvement of state-sponsored threat actors. The analysis below is based on information currently available, and definitive attribution requires a level of evidence that is not always publicly accessible.
The most direct state-nexus attribution points to APT-C-60. Multiple security organizations characterize this group as a state-sponsored advanced persistent threat actor operating out of East Asia. Their pattern of sustained, deliberate targeting of specific Japanese organizations reflects that character. The ongoing versioning of the custom SpyGlace malware, the technical sophistication of their detection evasion methods, and the carefully engineered attack infrastructure are not outputs that individuals or short-term criminal groups can produce quickly.
Regarding the SonicWall SMA1000 zero-day vulnerabilities, vulnerabilities in remote access products have a well-established history of being prioritized as initial access vectors by state-sponsored groups. The CISA warnings concerning FortiSandbox and SharePoint vulnerabilities should be understood in the same context. These attack surfaces share a common characteristic: they are preferred entry points for actors engaged in long-term espionage operations.
On the Patriot Bait botnet, Trend Micro's analysis indicates operation by Russian-speaking threat actors, though there is insufficient publicly available evidence at this time to assert direct state involvement. However, the capability to migrate C2 infrastructure in six minutes using AI suggests a technical and organizational depth that goes beyond standard financially motivated criminal groups. That observation is worth recording.
The ESET Threat Report H1 2026 explicitly notes increased APT activity targeting the Asia-Pacific region. This week's incidents should not be read as isolated events. They belong to a longer trend that is already underway.
DEFEND WITHOUT CHOOSING SIDES
Practical defensive actions drawn from this week's incidents
① Verify and apply firmware updates for SonicWall SMA1000 series devices immediately. With zero-day vulnerabilities confirmed as actively exploited in the wild, investigation and patching must proceed in parallel rather than sequentially. Review recent access logs for anomalies at the same time — do not defer that log review until after patching is complete.
② Apply the Microsoft July 2026 Patch Tuesday updates this week. Organizations running SharePoint, whether internally or externally facing, should treat this as highest priority. CISA has explicitly flagged active exploitation of the relevant vulnerabilities. Deciding that next week is soon enough is a decision to accept unnecessary risk.
③ Verify current versions of nginx and Firefox across all servers and endpoints in your environment and update to the latest releases without delay. Exploit code for the Firefox vulnerability is already publicly available, which means the available window is narrow. Use this occasion to evaluate whether your organization can enforce browser updates centrally rather than relying on individual users to apply them on their own.
④ Immediately brief HR and talent acquisition staff on the APT-C-60 campaign. Establish a clear procedure requiring staff to report any externally received LNK or ZIP files to the security team before opening them. Make explicit to your teams that download links served from legitimate platforms such as Proton Drive and GitHub can be weaponized — a recognized platform name does not mean a safe link.
⑤ Review this week's execution logs for mshta.exe and wscript.exe activity. APT-C-60 is actively abusing mshta.exe as a detection-resistant execution method. Confirm whether your EDR or SIEM alerting rules cover suspicious execution patterns involving these binaries, and add detection rules where they are missing. If logs are unavailable for this review, treat that gap as an immediate signal to revisit your logging configuration.
NEXT ISSUE
Next week, we continue tracking the evolving threat landscape — including any further developments on the APT-C-60 campaign targeting Japan and the ongoing exploitation of SonicWall and SharePoint vulnerabilities. See you Friday.
About us: This newsletter is written from Japan — a country that has been simultaneously targeted by three nation-states (China, Russia, and North Korea) for over a decade. Two of these three (China and Russia) are UN Security Council permanent members with veto power; one is a nuclear-armed state operating outside the international rules-based order. We are not American. We are not Chinese. We have no geopolitical agenda except one: helping ordinary people and small businesses in non-superpower countries protect themselves from digital warfare they never signed up for.
Written by a Japan-based information security professional with over 20 years of experience, in collaboration with AI assistants.
© 2026 Samurai Cyber Watch. Redistribution with attribution permitted for non-commercial use.