CUCKOO SPEAR Part 1: Analyzing NOOPDOOR from an IR Perspective
ID: eb89b6a1-a821-598f-af13-6f9693ec4548
STIX ID: report--eb89b6a1-a821-598f-af13-6f9693ec4548
Feed Name: Cybereason Blog
Threat Score
**Cuckoo Spear (Cybereason):** This report analyzes a sustained APT10 cyber-espionage campaign targeting Japanese and regional organizations, detailing the use of loaders (NOOPLDR variants, GOSICLoader, DOWNJPIT), backdoors (NOOPDOOR, LODEINFO), DGA-based C2 with internal pivoting, persistence via MSBuild scheduled tasks/WMI event consumers/service DLLs, exploited CVEs, observed IOCs, and provides detection guidance plus links to Yara rules and scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
