During Operation CuckooBees, the threat actors leveraged a custom tool to dump OS credentials and used following commands: reg save HKLM\\SYSTEM system.hiv, reg save HKLM\\SAM sam.hiv, and reg save HKLM\\SECURITY security.hiv, to dump SAM, SYSTEM and SECURITY hives.2
campaign
Operation CuckooBees C0012
- First seen
- December 2019
- Last seen
- May 2022
- Created
- 22 September 2022
- Last modified
- 31 July 2026
Operation CuckooBees was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019. Security researchers noted the goal of Operation CuckooBees, which was still ongoing as of May 2022, was likely the theft of proprietary information, research and development documents, source code, and blueprints for various technologies. Researchers assessed Operation CuckooBees was conducted by actors affiliated with Winnti Group, APT41, and BARIUM.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference C0012
During Operation CuckooBees, the threat actors collected data, files, and other information from compromised networks.3
During Operation CuckooBees, the threat actors used the net start command as part of their initial reconnaissance.4
During Operation CuckooBees, the threat actors used ipconfig, nbtstat, tracert, route print, and cat /etc/hosts commands.5
During Operation CuckooBees, the threat actors used the net view and ping commands as part of their advanced reconnaissance.6
During Operation CuckooBees, the threat actors executed an encoded VBScript file.7
Standing C0012
Reach is how much of ATT&CK this campaign touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 56 ATT&CK campaigns only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
89th percentile · 89% of 56 ATT&CK campaigns have this many Enterprise techniques or fewer.
68th percentile · 68% of 56 ATT&CK campaigns have this many tactics spanned or fewer.
63rd percentile · 63% of 56 ATT&CK campaigns have this many tools and malware or fewer.
55% of the population shares a single value across only 3 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
80th percentile · 80% of 56 ATT&CK campaigns have this many detection rules per technique or fewer.
Detection coverage C0012
1151 distinct rules cover the 33 techniques recorded for this campaign. The 1329 technique-to-rule mappings resolve to 1151 distinct rules, because one rule can cover several techniques. 760 Sigma · 391 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org