CUCKOO SPEAR Part 2: Threat Actor Arsenal
ID: 2ab58df4-61eb-5476-b6b9-23e559c82a36
STIX ID: report--2ab58df4-61eb-5476-b6b9-23e559c82a36
Feed Name: Cybereason Blog
This report presents a technical analysis of the Cuckoo Spear campaign attributed to APT10, detailing two loader variants (NOOPLDR-DLL and NOOPLDR-C#) and the NOOPDOOR shellcode: their persistence mechanisms (service DLL side-loading, msbuild XML), registry-stored encrypted shellcode and AES decryption tied to MachineId, advanced injection techniques using dynamic syscalls, a DGA-based C2 and custom TCP protocol, internal C2 server capabilities, and provided IOCs, detection queries, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
