HomeSecuritySolarWinds: Third malware used in attack found

SolarWinds: Third malware used in attack found

CrowdStrike , one of the security firms investigating the supply chain attack SolarWinds , said it had identified a third piece of malware that appears to be directly involved in the hack .

SolarWinds malware

The two previous malware discovered were Sunburst (Solorigate) and Teardrop. The new malware is called Sunspot.

According to CrowdStrike researchers, Sunspot was the first malware used by cybercriminals to carry out the attack.

Sunspot malware was running on SolarWinds build server

Crowdstrike states in report that Sunspot was developed when hackers first breached SolarWinds' internal network.

According to researchers, the Sunspot malware was installed on the SolarWinds build server. The malware's sole purpose was to monitor the build server for build commands related to Orion, one of SolarWinds' flagship products used by more than 33,000 customers (worldwide).

Upon detecting a build command, the malware silently replaced source code files in the Orion app with files that loaded the Sunburst malware. This resulted in versions of the Orion app that also installed the Sunburst malware.

These trojanized Orion clients arrived in official SolarWinds server updates and were installed on the networks of many of the company's customers.

Immediately afterwards, Sunburst was activated on the internal networks of SolarWinds' corporate and government client services, and collected data that it sent back to the hackers ( Symantec provides information on how to send data via DNS requests).

The attackers would then decide if a victim was important enough to compromise and use the more powerful Teardrop trojan. At the same time, Sunburst would be ordered to be removed from non-important or high-risk networks.

However, the revelation about the third malware involved in the SolarWinds attack is not the only one that has come to light in recent hours.

In a blog post, SolarWinds published a timeline of the attack. The company said that before deploying the Sunburst software between March and June 2020, the hackers had conducted some testing between September and November 2019.

“The October 2019 release of the Orion Platform contained modifications designed to test attackers’ ability to inject code into our systems,” said SolarWinds CEO Sudhakar Ramakrishna.

SolarWinds: Third malware used in attack found

The other discovery released by Kasperskyis that Sunburst bears similarities to malware used by the Russian hacking group Turla.

Kaspersky stressed that it simply found some similarities in the code and that this does not necessarily mean that the same group is behind the attack on SolarWinds.

Security companies are making more cautious statements about the possible perpetrator of the attack, although the US government has already said publicly that Russia responsible for the attack. is likely

Security companies recommend not making such statements yet, as the investigation is at an early stage.

Currently, the attackers are being tracked under different names, such as UNC2452 (FireEye, Microsoft), DarkHalo (Volexity), and StellarParticle (CrowdStrike), but the name is expected to change once the companies learn more.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS