logo

Dark Halo Leverages SolarWinds Compromise to Breach Organizations

ID: 3134846a-4ebf-5cd0-a3c1-8e64c1f343ce

STIX ID: report--3134846a-4ebf-5cd0-a3c1-8e64c1f343ce

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2020-12-14

Date Updated: 2026-05-01

...
...

Volexity documents attacks by a sophisticated actor they call Dark Halo (overlapping with FireEye's UNC2452) that used a backdoored SolarWinds Orion update to gain access, executed Exchange Management Shell and PowerShell commands to enumerate and export targeted mailboxes, bypassed Duo MFA by extracting the Duo integration secret to forge valid duo-sid cookies, staged and exfiltrated password-protected PSTs via OWA, and left numerous indicators (IPs, domains, SSL-hosted domains) and recommended mitigations such as resetting MFA integration keys and credentials and monitoring Exchange Management Shell activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.