logo

APT10 Targeting Japanese Corporations Using Updated TTPs

ID: 10e2021d-07d6-480d-9447-390a6178114e

STIX ID: report--10e2021d-07d6-480d-9447-390a6178114e

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2018-09-14

Last Modified Date: 2018-09-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes an APT10 spear-phishing campaign targeting Japanese organizations that delivered malicious Word documents with macros to install the UPPERCUT backdoor; the report details the full kill chain (drop, certutil decode, esentutil rename, Notepad++ GUP.exe sideload of a malicious libcurl.dll, shellcode unpacking, and updated backdoor functionality), network indicators (C2 domains/IPs, unique Cookie behavior, Blowfish key per-C2), and recommended mitigations such as disabling Office macros.