CN

BRONZE SPIRALBRONZE SPIRAL

Also known as: BRONZE SPIRAL

Origin
CN
Known aliases
1

Profile

In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platform software to deploy a web shell dubbed SUPERNOVA. CTU researchers track the operators of the SUPERNOVA web shell as BRONZE SPIRAL and assess with low confidence that the group is of Chinese origin. SUPERNOVA was likely deployed through exploitation of CVE-2020-10148, and CTU researchers observed post-exploitation reconnaissance commands roughly 30 minutes before the web shell was deployed. This may have been indicative of the threat actor conducting scan-and-exploit activity and then triaging for victims of particular interest, before deploying SUPERNOVA and attempting to dump credentials and move laterally. BRONZE SPIRAL has been associated with previous intrusions involving the targeting of ManageEngine servers, maintenance of long-term access to periodically harvest credentials and exfiltrate data, and espionage or theft of intellectual property. The threat group makes extensive use of native system tools and 'living off the land' techniques.

Aliases· 1

BRONZE SPIRAL

References

  1. https://unit42.paloaltonetworks.com/solarstorm-supernova
  2. https://www.guidepointsecurity.com/blog/supernova-solarwinds-net-webshell-analysis
  3. https://www.secureworks.com/blog/supernova-web-shell-deployment-linked-to-spiral-threat-group
  4. https://www.sentinelone.com/labs/solarwinds-understanding-detecting-the-supernova-webshell-trojan
  5. https://us-cert.cisa.gov/ncas/analysis-reports/ar21-027a
  6. https://www.cisa.gov/news-events/analysis-reports/ar21-112a

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
SUPERNOVA
Actor
BRONZE STARLIGHT
Actor
BRONZE SPRING
Actor
BRONZE VAPOR
Actor
BRONZE EDGEWOOD
Actor
BRONZE HIGHLAND
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.