Operation CuckooBees is a named intrusion campaign associated with advanced post-compromise reconnaissance and stealthy payload staging in enterprise environments. Observed activity includes extensive host and account discovery using native system utilities to identify the current user, enumerate logged-in users, gather account information, inspect administrative groups, and query domain environment details. The operators also performed system and network discovery by collecting host configuration data, enumerating drives, inspecting files and directories, identifying running services, and surveying local network configuration and active connections. Native commands were used to gather operating system details, drive information, service listings, routing and interface data, and Active Directory-related account information. The campaign also demonstrated defense-evasion tradecraft by storing payloads in Windows Common Log File System transactional logs rather than relying solely on conventional files on disk. Publicly referenced aliases are limited to naming variants of the campaign itself, including operation_cuckoobees and related campaign or threat-actor labels. Available information supports characterization as a reconnaissance-heavy intrusion campaign, but does not by itself establish a high-confidence country of origin, victim geography, or dominant motivation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign activity included broad host and network discovery using multiple native utilities across platforms.
Campaign in which operators used systeminfo to gather details about compromised systems.
Campaign using query user and whoami for advanced reconnaissance and user discovery.
Activity cluster in which operators used drive enumeration commands during reconnaissance.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.