logo

CUCKOO SPEAR Part 2: Threat Actor Arsenal

ID: 2ab58df4-61eb-5476-b6b9-23e559c82a36

STIX ID: report--2ab58df4-61eb-5476-b6b9-23e559c82a36

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2024-10-04

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

This report presents a technical analysis of the Cuckoo Spear campaign attributed to APT10, detailing two loader variants (NOOPLDR-DLL and NOOPLDR-C#) and the NOOPDOOR shellcode: their persistence mechanisms (service DLL side-loading, msbuild XML), registry-stored encrypted shellcode and AES decryption tied to MachineId, advanced injection techniques using dynamic syscalls, a DGA-based C2 and custom TCP protocol, internal C2 server capabilities, and provided IOCs, detection queries, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.