More clues appear to link SolarWinds hack to China

Researchers from the Counter Threat Unit (CTU) at Secureworks have discovered a possible link to China while examining how SolarWinds serv...

Researchers from the Counter Threat Unit (CTU) at Secureworks have discovered a possible link to China while examining how SolarWinds servers were used to deploy malware.

During the end of last year, a compromised internet-facing SolarWinds server was used as a springboard by hackers to deploy the .NET web shell Supernova. Based on similar intrusions which occurred on the same network, it appears that the Chinese-based Spiral threat group is responsible for both cases.

According to Secureworks' new report, the authentication bypass vulnerability in SolarWinds Orion API, tracked as CVE-2020-10148, that can lead to remote execution of API commands, has been actively exploited by Spiral. When vulnerable servers are detected and exploited, a script capable of writing the Supernova web shell to disk is deployed using a PowerShell command.

Supernova, which is written in .NET, is an advanced web shell that can maintain persistence on a compromised machine as well as compile “method, arguments and code data” in-memory according to a post from Palo Alto Network's Unit 42.

Supernova

During an incident observed by Secureworks that occurred last August, Supernova was used by Spiral to perform reconnaissance, domain mapping and to steal both credentials and information from a ManageEngine ServiceDesk server. This incident shares similarities to the one that occurred in November and was analyzed by the firm's Counter Threat Unit.

While these two cases are believed to be the work of the Spiral threat group, there is no link to the SolarWinds hack that occurred in December of last year.

To prevent falling victim to future attacks by Spiral, Secureworks recommends that organizations use available controls to restrict access to several IP addresses (which can be found here) that point to the threat group's C&C servers.

Via ZDNet



from TechRadar - All the latest technology news https://ift.tt/2OdwpX2
via IFTTT

COMMENTS

BLOGGER
Name

Latest from TechRadar,63, 9to5Mac,7, AI News & Artificial Intelligence | TechCrunch,2, Apple,10, Cointelegraph.com News,9, Electrek,5, Space Explored,2, Technology,108, The Verge,45, TrendlyNews,27, YouTube - 9to5Google,13,9to5Mac,10,AI,2,Apps,4063,Business,151,Camera,1162,Crypto,9,Earn $$$,3,Gadgets,1741,Games,927,GTA,1,IFTTT,7,Innovations,3,Mobile,1700,Paid Promotions,5,Promotions,5,Space,2,Sports,1,Technology,8809,Trailers,796,Travel,37,Trending,4,Trendly News,25458,TrendlyNews,342,Vehicles,5,Video,5,XIAOMI,13,YouTube - 9to5Google,219,
ltr
item
TrendlyNews | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Crypto #Ai #TrendlyNews: More clues appear to link SolarWinds hack to China
More clues appear to link SolarWinds hack to China
TrendlyNews | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Crypto #Ai #TrendlyNews
http://www.trendlynews.in/2021/03/more-clues-appear-to-link-solarwinds.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2021/03/more-clues-appear-to-link-solarwinds.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy