Dark Halo Leverages SolarWinds Compromise to Breach Organizations
ID: 3134846a-4ebf-5cd0-a3c1-8e64c1f343ce
STIX ID: report--3134846a-4ebf-5cd0-a3c1-8e64c1f343ce
Feed Name: Volexity Blog
Volexity documents attacks by a sophisticated actor they call Dark Halo (overlapping with FireEye's UNC2452) that used a backdoored SolarWinds Orion update to gain access, executed Exchange Management Shell and PowerShell commands to enumerate and export targeted mailboxes, bypassed Duo MFA by extracting the Duo integration secret to forge valid duo-sid cookies, staged and exfiltrated password-protected PSTs via OWA, and left numerous indicators (IPs, domains, SSL-hosted domains) and recommended mitigations such as resetting MFA integration keys and credentials and monitoring Exchange Management Shell activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
