Article 5D7NK Microsoft Details OPSEC, Anti-Forensic Techniques Used by SolarWinds Hackers

Microsoft Details OPSEC, Anti-Forensic Techniques Used by SolarWinds Hackers

by
Fnord666
from SoylentNews on (#5D7NK)

upstart writes in with an IRC submission for SoyCow639:

Microsoft Details OPSEC, Anti-Forensic Techniques Used by SolarWinds Hackers:

Microsoft on Wednesday released another report detailing the activities and the methods of the threat actor behind the attack on IT management solutions firm SolarWinds, including their malware delivery methods, anti-forensic behavior, and operational security (OPSEC).

The attackers, which some believe to be sponsored by Russia, breached SolarWinds' systems in 2019 and used a piece of malware named Sundrop to insert a backdoor tracked as Sunburst into the company's Orion product. Sunburst was delivered to thousands of organizations, but a few hundred victims that presented an interest to the attackers received several other pieces of malware and many of their systems were compromised using hands-on-keyboard techniques.

In the case of these victims, the hackers used loaders named Teardrop and Raindrop to deliver Cobalt Strike payloads.

In its latest report on the SolarWinds attack, which it tracks as Solorigate, Microsoft explains how the attackers got from the Sunburst malware to the Cobalt Strike loaders, and how they kept the components separated as much as possible to avoid being detected.

"What we found from our hunting exercise across Microsoft 365 Defender data further confirms the high level of skill of the attackers and the painstaking planning of every detail to avoid discovery," Microsoft said.

[...] While many of the tactics, techniques, and procedures (TTPs) leveraged by the attackers are already documented in the MITRE ATT&CK framework, Microsoft says it's working with MITRE to ensure that the new techniques observed in these attacks will also be added to the framework.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments