logo

Cuckoo Spear – the latest Nation-state Threat Actor targeting Japanese companies

ID: 72443c32-713f-5512-9808-6299ba972627

STIX ID: report--72443c32-713f-5512-9808-6299ba972627

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2024-07-25

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason's Threat Analysis 'Cuckoo Spear' attributes a long-running espionage campaign to APT10 that deploys LODEINFO and a newer modular backdoor NOOPDOOR (loaded by NOOPLDR) with DGA-based C2; the report documents spear-phishing and vulnerability exploitation for initial access, persistence via scheduled tasks, WMI consumer events and malicious service DLLs, multi-year dwell time, data exfiltration from critical infrastructure and academic targets, and provides IOCs and hunting queries for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.