SolarWinds Orion and UNC2452 - Summary and Recommendations
ID: 921965ca-9bec-59c1-a10b-bbf64414b5b9
STIX ID: report--921965ca-9bec-59c1-a10b-bbf64414b5b9
Feed Name: TrustedSec blog
Threat Score
### Executive Summary This TrustedSec guidance describes the SolarWinds Orion supply-chain compromise by the UNC2452 actor (SUNBURST backdoor) that distributed digitally signed, backdoored Orion updates (Mar–Jun 2020), discusses follow-on activity including TEARDROP memory-only droppers and Cobalt Strike deployment, and provides remediation, hunting guidance, Active Directory/Azure AD hardening recommendations, and references to IOCs and external technical resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
