Cuckoo Spear [B-Side]
Nov 20, 2024 · 30m
Summary
Cyberism’s Malicious Life features Gene Ito and Luis Castel from CyberReason discussing the Cuckoo Spear espionage campaign by Chinese APT-10. They analyze Noopdoor, a sophisticated malware with advanced persistence mechanisms like WMI and MSBuild, targeting Japanese critical infrastructure. The episode covers infiltration via spear phishing or firewall breaches, internal C2 relays, and Domain Generation Algorithms used to evade detection.
Topics discussed
Introduction to Cuckoo Spear and guests
Overview of LoadInfo malware and APT10 targets
CyberReason's investigation and victim discovery
Persistence mechanisms: Task Scheduler, MSBuild, WMI
Initial access methods: Spear phishing and firewall breaches
Sophistication of shellcode and C2 infrastructure
Strategic containment against advanced threat actors
Attack flow and internal C2 relay points
Use of Living off the Land binaries (LoLbins)
Domain Generation Algorithms (DGA) and blocking
APT10 attribution, resources, and global scope
Listen ad-free on Castria