logo

CUCKOO SPEAR Part 1: Analyzing NOOPDOOR from an IR Perspective

ID: eb89b6a1-a821-598f-af13-6f9693ec4548

STIX ID: report--eb89b6a1-a821-598f-af13-6f9693ec4548

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2024-09-13

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

**Cuckoo Spear (Cybereason):** This report analyzes a sustained APT10 cyber-espionage campaign targeting Japanese and regional organizations, detailing the use of loaders (NOOPLDR variants, GOSICLoader, DOWNJPIT), backdoors (NOOPDOOR, LODEINFO), DGA-based C2 with internal pivoting, persistence via MSBuild scheduled tasks/WMI event consumers/service DLLs, exploited CVEs, observed IOCs, and provides detection guidance plus links to Yara rules and scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.