Russian Intelligence Behind Widespread SolarWinds Supply Chain Cyberattack

The US government attributes a massive, ongoing cyberattack targeting government and critical infrastructure to the Russian SVR. The threat actor primarily exploits a compromised SolarWinds Orion update but also uses other methods like SAML token abuse.

The Cybersecurity and Infrastructure Security Agency (CISA) reveals that an advanced persistent threat (APT) actor linked to the Russian Foreign Intelligence Service (SVR) actively compromises U.S. government agencies, critical infrastructure entities, and private sector organizations. This ongoing campaign begins in at least March 2020 and demonstrates exceptional patience, operational security, and complex tradecraft. CISA warns that removing this highly skilled threat actor from compromised networks remains extremely complex and challenging for affected organizations.

A primary initial access vector for this widespread intrusion is a supply chain compromise involving a specific Dynamic Link Library (DLL) within SolarWinds Orion platform products. The malicious code affects several specific versions of the Orion Platform released in 2019 and 2020, allowing the attackers to infiltrate networks seamlessly through legitimate software updates. This compromised update serves as a trojanized gateway that bypasses traditional security perimeters.

CISA emphasizes that the SolarWinds compromise is not the only method of entry for this APT group. Investigators uncover evidence of additional initial access vectors, including the abuse of legitimate accounts and the manipulation of Security Assertion Markup Language (SAML) tokens. In some cases, networks show clear indicators of this adversary's SAML token abuse even without the presence of impacted SolarWinds instances, prompting ongoing investigations into the full scope of the attack.

Read More at the original source →