ATT&CKCampaignsOperation CuckooBees

Operation CuckooBees

C0012

Campaign, Dec 2019 to May 2022.View on attack.mitre.org

About this campaign

Operation CuckooBees was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019. Security researchers noted the goal of Operation CuckooBees, which was still ongoing as of May 2022, was likely the theft of proprietary information, research and development documents, source code, and blueprints for various technologies. Researchers assessed Operation CuckooBees was conducted by actors affiliated with Winnti Group, APT41, and BARIUM.

Techniques used33

Procedure examples33

TechniqueProcedure example
T1003.002
Security Account Manager

During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: `reg save HKLM\\SYSTEM system.hiv`, `reg save HKLM\\SAM sam.hiv`, and `reg save HKLM\\SECURITY security.hiv`, to dump SAM, SYSTEM and SECURITY hives.

T1005
Data from Local System

During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.

T1007
System Service Discovery

During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance.

T1016
System Network Configuration Discovery

During Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands.

T1018
Remote System Discovery

During Operation CuckooBees, the threat actors used the `net view` and `ping` commands as part of their advanced reconnaissance.

T1027.010
Command Obfuscation

During Operation CuckooBees, the threat actors executed an encoded VBScript file.

T1027.011
Fileless Storage

During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs.

T1033
System Owner/User Discovery

During Operation CuckooBees, the threat actors used the `query user` and `whoami` commands as part of their advanced reconnaissance.

T1036.005
Match Legitimate Resource Name or Location

During Operation CuckooBees, the threat actors renamed a malicious executable to `rundll32.exe` to allow it to blend in with other Windows system files.

T1049
System Network Connections Discovery

During Operation CuckooBees, the threat actors used the `net session`, `net use`, and `netstat` commands as part of their advanced reconnaissance.

T1053.005
Scheduled Task

During Operation CuckooBees, the threat actors used scheduled tasks to execute batch scripts for lateral movement with the following command: `SCHTASKS /Create /S <IP Address> /U <Username> /p <Password> /SC ONCE /TN test /TR <Path to a Batch File> /ST <Time> /RU SYSTEM.`

T1057
Process Discovery

During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance.

T1059.003
Windows Command Shell

During Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance.

T1059.005
Visual Basic

During Operation CuckooBees, the threat actors executed an encoded VBScript file using `wscript` and wrote the decoded output to a text file.

T1069.001
Local Groups

During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance.

View all 33 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software2

References1

  1. Cybereason OperationCuckooBees May 2022 Open source
    Cybereason Nocturnus. (2022, May 4). Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques. Retrieved September 22, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.