Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybereason’s Cuckoo Spear reporting ties multiple incidents to the APT10 intrusion set and describes long-duration stealthy persistence in Japanese victim networks, with NOOPDOOR and NOOPLDR as important elements of the newer arsenal.
Cybereason’s Cuckoo Spear reporting ties multiple incidents to the APT10 intrusion set and describes long-duration stealthy persistence in Japanese victim networks, with NOOPDOOR and NOOPLDR as important elements of the newer arsenal.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution chain - Installation Scheduled task ... Example: automatic-device-check or createobject
The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution. | Many malware families store configuration, payloads, encryption keys, C2 addresses, or other operational data in Registry keys, such as QakBot storing configuration in a randomly named subkey under HKCU\Software\Microsoft and PolyglotDuke writing encrypted JSON configuration files to the Registry.
The content repeatedly describes adversaries using Base64, XOR, RC4, AES, hexadecimal encoding, string encryption, code flattening, custom crypters, and other obfuscation methods to hide payloads, strings, configuration data, URLs, and scripts.
Defined Windows utility ... Example: perfmon.exe, wermgr.exe, or powercfg.exe ... injects payload into
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution. | Many malware families store configuration, payloads, encryption keys, C2 addresses, or other operational data in Registry keys, such as QakBot storing configuration in a randomly named subkey under HKCU\Software\Microsoft and PolyglotDuke writing encrypted JSON configuration files to the Registry.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader component in newer APT10-related arsenal, paired with NOOPDOOR in reporting on Japanese intrusions.
NOOPLDR is a shellcode loader used to deploy NOOPDOOR. It exists in two forms: an XML/C# loader executed via MSBuild and a DLL loader used via side-loading. Both decrypt and store payloads in the registry using machine-specific keys, and employ anti-analysis and obfuscation techniques.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.