Overview
Operation CuckooBees (MITRE ATT&CK ID C0012) was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019, per MITRE’s campaign profile. MITRE documents the campaign as still ongoing as of May 2022, with the likely goal — per cited security researchers — being theft of proprietary information, research and development documents, source code, and blueprints for various technologies. MITRE’s citations attribute the campaign to actors affiliated with Winnti Group, APT41, and BARIUM.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from December 2019 to May 2022 — a notably long-running operation compared to most other campaigns in this batch.
Named actors and tools (per MITRE’s description vs. our relationship data)
MITRE’s description text names Winnti Group, APT41, and BARIUM as affiliated actors. We checked this directly against MITRE’s raw published STIX bundle (not just our own ingested copy): every one of this campaign’s 26 relationship objects is a technique/tool “uses” edge — there is no “attributed-to” edge to any group at all in MITRE’s own source data. This is a genuine gap in MITRE’s upstream data, not an ingestion issue on our side. We report the actor names as MITRE’s own prose synthesis, not as something its structured relationship graph confirms.
What we don’t have
As noted above, the three actor names in MITRE’s description aren’t backed by a structured relationship edge in our ingested data. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no confirmation of whether the campaign concluded after May 2022 or continued undocumented in MITRE’s more recent updates.
Frequently Asked Questions
What was Operation CuckooBees? A long-running cyber espionage campaign, per MITRE ATT&CK, targeting technology and manufacturing intellectual property since at least 2019, documented as ongoing through May 2022.
Who was behind Operation CuckooBees? MITRE’s description text attributes it to actors affiliated with Winnti Group, APT41, and BARIUM — though this naming isn’t backed by a formal relationship edge in our ingested structured data.
What was the campaign’s objective? Per MITRE’s citations of security researchers, likely theft of proprietary information, R&D documents, source code, and technology blueprints.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0012, aggregated September 4, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.