Cuckoo Spear – the latest Nation-state Threat Actor targeting Japanese companies
ID: 72443c32-713f-5512-9808-6299ba972627
STIX ID: report--72443c32-713f-5512-9808-6299ba972627
Feed Name: Cybereason Blog
Cybereason's Threat Analysis 'Cuckoo Spear' attributes a long-running espionage campaign to APT10 that deploys LODEINFO and a newer modular backdoor NOOPDOOR (loaded by NOOPLDR) with DGA-based C2; the report documents spear-phishing and vulnerability exploitation for initial access, persistence via scheduled tasks, WMI consumer events and malicious service DLLs, multi-year dwell time, data exfiltration from critical infrastructure and academic targets, and provides IOCs and hunting queries for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
