Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

1/12/2021
06:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

More SolarWinds Attack Details Emerge

A third piece of malware is uncovered, but there are still plenty of unknowns about the epic attacks purportedly out of Russia.

As yet another piece of malware has been uncovered in the attack on SolarWinds network management system software, there still remain several missing elements needed to draw a complete picture of the massive cyberattacks against major US government agencies and corporations, including security vendor and incident response expert FireEye.

SolarWinds and CrowdStrike this week detailed a third malware tool — dubbed Sunspot — that was found in the attack on the software vendor. Sunspot is a custom program that inserted the so-called Sunburst backdoor into the software build environment of SolarWinds' Orion network management product. CrowdStrike, which analyzed Sunspot on behalf of SolarWinds, says the tool was carefully planted somehow by the attackers and kept hidden from SolarWinds developers with sophisticated tracking and camouflaging so it couldn't be detected.

"This is a purpose-built tool," says Adam Meyers, vice president of intelligence at CrowdStrike.

Related Content:

SolarWinds Hack Lessons Learned: Finding the Next Supply Chain Attack

How Data Breaches Affect the Enterprise

New From The Edge: Cartoon: Shakin' It Up at the Office

In a rare reversal of roles when it comes to nation-state attribution, the US intel community has publicly cited Russia as the perpetrator in the attacks, while security firms FireEye and CrowdStrike, which specialize in nation-state activity, have been unusually cautious in identifying a threat group or nation behind the attacks. Neither vendor will confirm whether it's Russia.

FireEye CEO Kevin Mandia last week noted during an Aspen Institute panel event that the attack group here "smells a lot different" despite similarities in its behavior to known nation-states. FireEye was the first to spot and report the attack on SolarWinds' software after discovering its own SolarWinds implementation had been targeted and that user credentials and its red-team tools had been stolen.

The attackers planted malware in legitimate updates to SolarWinds' Orion network management software that was sent to some 18,000 public and private sector customers of the software. According to US intelligence assessments, a very small number of those organizations actually were targeted and compromised.

"This is a pretty complex attack," CrowdStrike's Meyers says. "They've got absolutely immaculate opsec from what we've seen."

Case in point: The source code for Sunburst was embedded in Sunspot, he explains, but the attackers had done something he had never seen before. "We were excited to see source code for Sunburst but realized they had run it through a decompiler and laundered the code" so it was sanitized and left no fingerprints or other clues, he says.

The Sunspot implant also could be repurposed, he notes, and used with other source code by the attackers.

SolarWinds, which recently hired former CISA director Christopher Krebs and former Facebook security head Alex Stamos to assist in their breach recovery process, said the attackers appear to have first infiltrated the firm in September 2019 — likely for reconnaissance. According to a blog post by SolarWinds' newly appointed president and CEO Sudhakar Ramakrishna, the October 2019 version of Orion was modified such that the attackers could test their ability to insert code into its builds. The attackers began using Sunspot to insert Sunburst into Orion releases, starting on Feb. 20, 2020; the attackers later removed Sunburst in June of last year.

CrowdStrike's Meyers recommends that organizations "take a hard look" at their software build environments, especially if they are shipping code. "We see a lot of threat actors interested in targeting the supply chain," he says. "Awareness is key."

Aside from Sunspot and Sunburst, there's also Teardrop malware, a memory-based dropper that was used by the attackers to run a custom Cobalt Strike Beacon service for the attackers.

Turla Thread?
Kaspersky researchers, meanwhile, also found several commonalities between the Sunburst backdoor and a known backdoor called Kazuar, which was first detailed by Palo Alto Networks in 2017 and used for cyber-espionage campaigns by the Turla group. Turla is a Russian advanced persistent threat also known by the names of Snake, Venomous Bear, Uroburos, Group 88, and Waterbug, and is associated with cyber espionage.

Sunburst and Kazuar have some code overlap — specifically in their victim UID-generation algorithm, sleeping algorithm, and FNV-1a hash use, Kaspersky found. That doesn't prove they are from the same attack group, however, but the code could be somehow related or merely mimicked, according to Kaspersky.  

"We don't fully understand all of the different vectors or scope of this compromise," says Costin Raiu, director of Kaspersky's global research and analysis team. "But any bits of technically connected information can help."

Aside from the SolarWinds attack vector, there also are unsolved threads of additional initial attack vectors, including stolen credentials, according to CISA, which is looking into other attack methods in the campaign. There's also the December alert from the NSA warning of a VMware zero-day vulnerability that has some researchers, including Kaspersky's Raiu, wondering if it could be somehow related to the SolarWinds attacks, possibly as one of the other initial attack vectors outside of the SolarWinds software.

Either way, the supply chain attack via SolarWinds has the earmarks of nation-states, including Russia.

"I see SolarWinds [the attack] as a very natural element of an ecosystem that has existed" in cyber espionage for some time, says Gregory Rattray, co-founder and partner at Next Peak and former global CISO of JP Morgan Chase, who also served as White House cybersecurity director during the George W. Bush administration.

Rattray — who coined the now commonly used term for nation-state hackers, advanced persistent threat, or APT, while in the US Air Force — says the SolarWinds attack is just one of likely many similar supply chain compromises by stealthy and sophisticated groups.

"We're only seeing the tip of the iceberg. … There's a whole lot more of this."

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
InterceptorR
50%
50%
InterceptorR,
User Rank: Apprentice
1/14/2021 | 12:41:27 PM
Revamp the code
Wow, just wow. Time to recode the entire thing on airgapped systems and trust only '3 kings' to update and import anything to the new code. This will take months. Not even SSL connectivity is safe anymore. 
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...