SAMURAI CYBER WATCH

Issue #17 — August 28, 2026

Practical Cyber Intelligence for Business Leaders in Non-Superpower Nations

THIS WEEK'S BRIEFING

APT-C-60 Stacks Four Trusted Platforms as Cover — and Japan's Structural Vulnerabilities Keep the Door Open

APT-C-60 routes C2 traffic through GitHub, GitLab, jsDelivr, and Codeberg simultaneously. A UK power facility forced offline. RedC2 arrives via npm. Twenty-one critical vulnerabilities in UniFi OS. This week's incidents share one thread: the perimeter assumptions defenders have relied on are no longer valid.

THE KEY DEVELOPMENT

APT-C-60 CONTINUES TO BREACH JAPANESE ORGANIZATIONS — EXPLOITING TRUSTED SERVICES AS COVER

A threat analysis published by JPCERT/CC Eyes on July 13, 2026, titled "Attacks on Japanese Organizations by Threat Actor APT-C-60," brings the group's persistence and technical sophistication into sharp focus.

The initial access vector is a spear-phishing email distributing a RAR archive via Proton Drive, an encrypted cloud storage service. Once the victim extracts the archive, an LNK file invokes mshta.exe to execute JavaScript, triggering the infection chain. The final payload is the SpyGlace backdoor, versions 3.1.15 through 3.1.18. According to JPCERT/CC's report, at least 24 endpoints had been confirmed compromised at the time of publication.

What makes this campaign technically notable is the design of its C2 infrastructure. APT-C-60 is reported to be routing command-and-control traffic through four legitimate developer platforms — GitHub, GitLab, jsDelivr, and Codeberg — in combination. These domains are unconditionally permitted through the firewalls of many Japanese organizations. Detecting malicious activity from communication logs alone is extremely difficult, and that is precisely the point of this approach. The abuse of legitimate services is becoming a standard technique in APT operations, but stacking this many trusted platforms simultaneously signals a deliberate and disciplined commitment to detection evasion.

Also worth noting is that the targets are described broadly as "organizations in Japan" rather than any specific sector. This non-specific framing suggests that a wide-scope intelligence-gathering campaign is ongoing.

JAPAN LENS: JAPAN REMAINS A CHOSEN TARGET — TIME TO CONFRONT THE STRUCTURAL PROBLEMS BEHIND IT

Looking at this week's incident list, the concentration of Japan-related cases is difficult to ignore. Alongside APT-C-60's ongoing espionage campaign, the week saw an HTML injection vulnerability in the government-operated My Number Point app provided by the Digital Agency, a faculty email account compromise at Nihon University's College of Law, and a lost hard drive at the National Center for Global Health and Medicine. This many incidents converging in a single week is not coincidence.

After more than two decades in this industry, I can say with confidence that Japan's recurring role as a target reflects structural problems. Many organizations hold technically advanced products and infrastructure while their investment in security and talent development continues to lag behind. Universities, hospitals, and other public-interest institutions have a persistent tendency to deprioritize security measures citing budget constraints. Meanwhile, the expanding adoption of national digital services — including the My Number system — is steadily increasing Japan's target value in the eyes of threat actors.

APT-C-60's tactics challenge a fundamental assumption underlying network defense at many Japanese organizations today: that traffic to trusted domains is inherently safe. That assumption no longer holds. Zero trust is no longer a conceptual discussion — it is a practical question of how and when to implement it. The My Number Point app vulnerability is reportedly being patched, but the speed of public communication and the actual update adoption rate remain serious concerns. From a national cyber hygiene standpoint, there is little room for optimism.

BEYOND THE EPICENTER: "WE'RE NOT A TARGET" IS THE RISK NOBODY SEES COMING

If any small or mid-sized business owner reads this week's incident roundup and concludes that APTs only go after large enterprises and government agencies, that assumption needs urgent revision.

The cyberattack on a UK power generation facility that forced an operational shutdown is a concrete illustration of the real economic cost when physical infrastructure goes offline. If a smaller organization is connected to a critical infrastructure operator as part of a supply chain, it is a viable pivot point for attackers seeking deeper access.

RedC2 — an AI-enabled Linux implant distributed through the npm supply chain — demonstrates that any organization with a development environment can become a victim. The open-source packages your engineers use every day can be the entry point. That is today's reality.

The vulnerabilities identified in WatchGuard Firebox and Ubiquiti UniFi OS disproportionately affect small and mid-sized organizations. Both product lines are widely deployed in that segment due to their affordable cost and ease of management. Of the 22 vulnerabilities confirmed in UniFi OS, 21 are rated critical. Leaving these unpatched is the organizational equivalent of walking out the door without locking it. The email account compromise at Nihon University's College of Law is another reminder that cloud email incidents can happen at any organization, regardless of size. The premise that only large targets get hit no longer reflects reality.

STATE ACTOR WATCH: THIS WEEK'S NATION-STATE SIGNALS — APT-C-60, THE UK POWER FACILITY ATTACK, AND REDC2

Multiple incidents this week carry indicators of potential nation-state involvement. I want to be direct about my assessments.

The clearest nation-state signal is the APT-C-60 espionage campaign against Japanese organizations. Multiple security researchers have reported analytical links between this group and a specific nation-state. The group is assessed to possess the long-term operational capability required for sustained intelligence collection. The fact that SpyGlace versions span 3.1.15 through 3.1.18 implies ongoing development and maintenance over a period of at least several months — a resource commitment that would be difficult to sustain without state-level backing.

The attack on the UK power generation facility targeted critical infrastructure, which points toward the involvement of a state or near-state-level actor. No official attribution has been confirmed at this time, but attacks on energy infrastructure cannot be assessed in isolation from the broader geopolitical context.

Regarding RedC2, the sophisticated integration of AI capabilities for prompt-driven payload manipulation suggests a well-resourced actor. That said, attribution at this stage should remain cautious. Technical sophistication and state sponsorship are not always correlated.

DEFEND WITHOUT CHOOSING SIDES

Practical defensive actions drawn from this week's incidents

① Build visibility into traffic destined for legitimate cloud services. APT-C-60 abused GitHub, GitLab, jsDelivr, and Codeberg as C2 channels. Blocking these domains outright is not operationally realistic for most organizations, but building a logging capability that captures destination URLs, endpoints, and user agents is something you can start on immediately. The ability to detect anomalous timing and frequency patterns in outbound traffic is your first line of defense against this class of attack.

② Apply emergency patches for WatchGuard Firebox and Ubiquiti UniFi OS as a top priority. Twenty-one out of 22 critical-rated vulnerabilities in UniFi OS is an abnormal severity profile. Confirm your patch status before the weekend.

③ Urgently audit npm and other package dependencies in your development environments. RedC2 was distributed via the npm supply chain. Establish a routine practice of auditing package-lock.json and yarn.lock files to detect unauthorized packages early.

④ Verify multi-factor authentication enrollment across all user accounts. The email account compromise at Nihon University's College of Law was, according to reporting, likely preventable with proper MFA in place. The key question is not whether MFA has been configured — it is whether every user is actually using it. There is often a significant gap between what has been set up and what is actually in use.

⑤ Review your physical media inventory records this week. The lost hard drive at the National Center for Global Health and Medicine was not a technical attack — it was a physical control failure. Establish a centralized log for the disposal, loan, and movement of portable storage media such as hard drives and USB devices, and formalize at least a semi-annual physical inventory check as organizational policy. Physical security is routinely underweighted in cybersecurity discussions, and attackers take advantage of exactly that gap.

NEXT ISSUE

Next week, we continue tracking the evolving threat landscape — including any further developments on the APT-C-60 campaign and the UK critical infrastructure attack. See you Friday.

About us: This newsletter is written from Japan — a country that has been simultaneously targeted by three nation-states (China, Russia, and North Korea) for over a decade. Two of these three (China and Russia) are UN Security Council permanent members with veto power; one is a nuclear-armed state operating outside the international rules-based order. We are not American. We are not Chinese. We have no geopolitical agenda except one: helping ordinary people and small businesses in non-superpower countries protect themselves from digital warfare they never signed up for.

Written by a Japan-based information security professional with over 20 years of experience, in collaboration with AI assistants.

© 2026 Samurai Cyber Watch. Redistribution with attribution permitted for non-commercial use.