HomeSecuritySolarWinds Sunburst backdoor: Common elements with Russian APT group malware

SolarWinds Sunburst backdoor: Common elements with Russian APT group malware

Kaspersky security researchers have found that the Sunburst backdoor, the malware deployed during the SolarWinds supply-chain attack , shares common characteristics with Kazuar, a .NET backdoor that has been linked to the Russian hacking group Turla.

SolarWinds Sunburst backdoor
SolarWinds Sunburst backdoor: Common elements with Russian APT group malware

Turla, which is also known as VENOMOUS BEAR and Waterbug , has been carrying out espionage and data theft campaigns since 1996 and, for many experts, is the main suspect for the attacks on the Pentagon, NASA, US Central Command and the Finnish Ministry of Foreign Affairs.

Kazuar is one of the tools used during previous Russian Turla attacks. According to Kaspersky researchers, it shares many features with the software used by the group behind the SolarWinds attack (this group is tracked under the names UNC2452 and DarkHalo).

spokesperson , as well as the FBI, CISA and NSA , have also stated that the perpetrator of the attack is likely a Russian APT group.

SolarWinds Sunburst backdoor: Common elements with Russian APT group malware
SolarWinds Sunburst backdoor: Common elements with Russian APT group malware

Code similarities

Samples of the Kazuar backdoor show significant similarities with Sunburst.

One of the common features is the algorithm used to generate UIDs for victims (unique victim identifiers), the extensive use of the FNV-1a hash in both malware , and the sleeping algorithm used by the Kazuar and Sunburst backdoors.

Kaspersky also points out that despite the similarities, the algorithms used to implement these overlapping capabilities are still not 100% identical. Therefore, they believe there is some connection between the two malware but “the nature of this connection is not yet entirely clear.”

The code snippets revealing the overlap show that “some sort of similar thought process was used to develop the Kazuar and Sunburst backdoors.”

Kaspersky has given a few possible explanations for the above similarities:

  • Το Sunburst αναπτύχθηκε από την ίδια ομάδα που δημιούργησε και το Kazuar backdoor
  • Οι προγραμματιστές του Sunburst υιοθέτησαν κάποιες ιδέες ή τμήματα κώδικα από το Kazuar, χωρίς να έχουν άμεση σύνδεση (εμπνεύστηκαν από το Kazuar)
  • Και οι δύο ομάδες, η DarkHalo / UNC2452 και η ομάδα που χρησιμοποιεί το Kazuar (Turla), απέκτησαν το κακόβουλο λογισμικό τους από την ίδια πηγή
  • Some of Kazuar's developers became members of another hacking group, using ideas and tools from the previous one and creating similar malware.
  • The developers of the Sunburst backdoor thought of leveraging elements of another known malware so as not to draw attention to themselves and to link the attacks to another hacking group.

Kaspersky researchers pointed out that the latter explanation is very likely. The developers of the Sunburst backdoor may have intentionally included the common features to mislead experts and shift blame for the attack on SolarWinds elsewhere.

“While Kazuar and Sunburst are linked, the nature of this relationship is not yet clear,” Kaspersky said. “Through further analysis, it is possible that evidence will emerge that confirms one or more of the above explanations.”

“To be clear – we are NOT saying that DarkHalo/UNC2452, the team using Sunburst, and Turla are necessarily the same team“.

However, it appears that the developers of Sunburst and Kazuar possibly knew the feature changes in each software, which shows a connection between the two.

SolarWinds Sunburst backdoor: Common elements with Russian APT group malware
SolarWinds Sunburst backdoor: Common elements with Russian APT group malware

The Sunburst backdoor first appeared in December, when the SolarWinds attack was first reported. Kazuar, on the other hand, has been heavily modified since its original form, when it was first detected in attacks in 2017. However, Kazuar samples are rarely uploaded to malware analysis platforms like VirusTotal, making it difficult to track changes.

“This connection does not indicate who was behind the attack on SolarWinds, however, it provides more information that can help researchers move forward with this investigation,” said Costin Raiu, director of Kaspersky Global Research and Analysis Team (GReAT).

“We believe it is important for other researchers around the world to investigate these similarities and try to uncover more evidence about Kazuar and the origins of Sunburst.“.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS