Supply Chain Exploitation of SolarWinds Orion Software | Huntress
ID: 16cb645f-d4ca-5629-9a41-136eea2f70b5
STIX ID: report--16cb645f-d4ca-5629-9a41-136eea2f70b5
Feed Name: Huntress Blog
Threat Score
FireEye and others discovered a SolarWinds Orion supply-chain compromise (SUNBURST/Solorigate) in which malicious, digitally-signed Orion updates (notably SolarWinds.Orion.Core.BusinessLayer.dll) were distributed between March and June 2020, enabling stealthy backdoor access, C2 communications, and in some cases administrative access and SAML token signing compromise; the report includes mitigation guidance, detection updates, and filesystem locations/IOCs for hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
