CyberSecurity Research

Cuckoo Spear Attacking Windows Users With Highly Sophisticated Malware

Researchers uncovered Cuckoo Spear, a new threat actor associated with the APT10 group, demonstrating persistent stealthy operations within victim networks for two to three years. 

The advanced persistent threat (APT) utilizes novel techniques and tools to conduct cyber espionage, emphasizing the critical need for robust security protocols, continuous threat monitoring, and collaborative intelligence sharing among organizations and governments to counter sophisticated nation-state adversaries like APT10. 

Since December 2019, the LODEINFO malware, attributed to the Chinese state-sponsored APT10 group, has been actively targeting critical infrastructure and academic sectors.

Recent investigations linked LODEINFO to the new NOOPDOOR malware, collectively termed “Cuckoo Spear.”.

How to Build a Security Framework With Limited Resources IT Security Team (PDF) - Free Guide

It leverages both malware variants for persistent network infiltration and data exfiltration, strongly indicating espionage as the primary motive.

The overlap in tactics, victims, and malware arsenal with previous APT10 operations, including “Earth Kasha” and “MirrorFace,” solidifies the attribution to this sophisticated threat actor. 

It has been identified that NOOPDOOR, a sophisticated 64-bit modular backdoor using DGA-based C2 communication, is loaded by the NOOPLDR decryptor, which threat actors employ in multi-stage attacks. 

LODEINFO, a primary backdoor, installs NOOPDOOR as a secondary backdoor to maintain persistent access within compromised networks for over two years. 

NOOPDOOR provides long-term covert operations, while LODEINFO likely serves as the initial infection vector and command-and-control channel. 

Cybereason’s research team, comprising Jin Ito, Loic Castel, and Kotaro Ogino, has comprehensively investigated the latest NOOPDOOR and NOOPLDR malware variants, detailing their advanced functionalities and tactics within a Threat Analysis Report. 

Their analysis delves into the malware’s sophisticated capabilities, including DGA-based C2 communication, decryption mechanisms, and modular architecture, shedding light on the threat actor’s evolving arsenal and techniques for stealthy infiltration, data exfiltration, and persistent network foothold. 

Recent incident response efforts uncovered a sophisticated threat actor toolset designed for covert intrusion, data exfiltration, and persistent control. 

Advanced reverse engineering revealed a primary reliance on spear phishing, specifically LODEINFO, for initial access, underscoring the need for robust defenses against evolving threat actor tactics. 

The threat actors are deploying NOOPDOOR through Scheduled Tasks and WMI Consumer Events to establish persistence.

In the first method, MSBuild is abused to compile a malicious XML file into the NOOPDOOR loader. 

The second method exploits WMI event consumers, triggering ActiveScript execution and subsequently leveraging MSBuild for NOOPDOOR compilation.

Both techniques demonstrate the adversaries’ adaptability in utilizing system tools for malicious purposes. 

Threat actors establish persistent access to compromised systems by installing malicious Windows services and loading unsigned dynamic-link libraries (DLLs) into memory. 

It allows attackers to execute malicious code with elevated privileges, maintain covert operations, and evade detection by security solutions that rely on signature-based detection methods.

Are you from SOC and DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Free Access

Aman Mishra

Aman Mishra is Security Reporter at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago