ShadowTalk Update: Sunburst, Sunspot, and more on SolarWinds!
ID: c5d23e6c-bd66-5475-9fe7-83aa111233c6
STIX ID: report--c5d23e6c-bd66-5475-9fe7-83aa111233c6
Feed Name: ReliaQuest Blog
ShadowTalk's intelligence summary covers major developments in the SolarWinds supply-chain compromise, reporting that SUNSPOT was used to implant the SUNBURST backdoor into Orion updates and that SUNBURST shares code similarities with the Kazuar backdoor (linked to Turla). The briefing also discusses a possible SolarWinds data-scam (SolarLeaks), a potentially compromised certificate reported by Mimecast, newly identified SUNSPOT malware, and separate ransomware activity attributed to APT27 and DarkSide.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
