Sophisticated Supply Chain Attack Targets Global Organizations via SolarWinds

FireEye uncovers a widespread global intrusion campaign that uses trojanized SolarWinds Orion updates to distribute the SUNBURST backdoor. The highly evasive threat actors, now attributed to APT29, use advanced techniques to blend in with legitimate network traffic.

FireEye uncovers a widespread global intrusion campaign that leverages a compromised software supply chain to breach numerous public and private organizations. The threat actors, originally tracked as UNC2452 and now attributed to APT29, gain access to victims by trojanizing updates to SolarWinds Orion IT monitoring software. This highly skilled operation begins as early as Spring 2020 and remains ongoing as attackers conduct lateral movement and data theft.

The attackers distribute a backdoor, tracked as SUNBURST, through a legitimately signed SolarWinds component called SolarWinds.Orion.Core.BusinessLayer.dll. After remaining dormant for up to two weeks, the malware communicates via HTTP to third-party servers to retrieve and execute various commands. These commands allow the attackers to transfer files, execute programs, profile the system, reboot the machine, and disable system services.

To evade detection, SUNBURST masquerades its network traffic as the legitimate Orion Improvement Program protocol and stores reconnaissance data within standard plugin configuration files. The backdoor also employs multiple obfuscated blocklists to avoid operating in environments that might expose its presence. Despite these highly evasive techniques, FireEye releases specific signatures to detect the threat actor and the supply chain attack in the wild.

Read More at the original source →