TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
ID: 139bca66-b3c7-5392-99d9-4b2bc70a8796
STIX ID: report--139bca66-b3c7-5392-99d9-4b2bc70a8796
Feed Name: NCC Research
NCC Group reports that TA505 has been exploiting SolarWinds Serv-U CVE-2021-35211 to gain remote code execution, using Base64 PowerShell to deploy Cobalt Strike beacons and Clop ransomware; the actor also achieves persistence by hijacking the RegIdleBackup scheduled task and storing a FlawedGrace RAT loader in registry CLSID objects. The report provides detection guidance (Serv-U DebugSocketlog.txt exceptions, Windows Event ID 4104 PowerShell logs, and registry CLSID checks), remediation advice to update Serv-U to at least 15.2.3 HF2, and internet scan data showing thousands of potentially vulnerable Serv-U instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
