APT10 Targeting Japanese Corporations Using Updated TTPs
ID: 10e2021d-07d6-480d-9447-390a6178114e
STIX ID: report--10e2021d-07d6-480d-9447-390a6178114e
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2018-09-14
Last Modified Date: 2018-09-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes an APT10 spear-phishing campaign targeting Japanese organizations that delivered malicious Word documents with macros to install the UPPERCUT backdoor; the report details the full kill chain (drop, certutil decode, esentutil rename, Notepad++ GUP.exe sideload of a malicious libcurl.dll, shellcode unpacking, and updated backdoor functionality), network indicators (C2 domains/IPs, unique Cookie behavior, Blowfish key per-C2), and recommended mitigations such as disabling Office macros.
