RUconfidence: 100G0118

UNC2452UNC2452

Also known as: DarkHalo · StellarParticle · NOBELIUM · Solar Phoenix · Midnight Blizzard · UNC2452

Origin
RU
Known aliases
6
Attribution
100

Profile

Reporting regarding activity related to the SolarWinds supply chain injection has grown quickly since initial disclosure on 13 December 2020. A significant amount of press reporting has focused on the identification of the actor(s) involved, victim organizations, possible campaign timeline, and potential impact. The US Government and cyber community have also provided detailed information on how the campaign was likely conducted and some of the malware used. MITRE’s ATT&CK team — with the assistance of contributors — has been mapping techniques used by the actor group, referred to as UNC2452/Dark Halo by FireEye and Volexity respectively, as well as SUNBURST and TEARDROP malware.

Aliases· 6

DarkHaloStellarParticleNOBELIUMSolar PhoenixMidnight BlizzardUNC2452

MITRE ATT&CK Group crosswalk

G0118

References

  1. https://medium.com/mitre-attack/identifying-unc2452-related-techniques-9f7b6c7f3714
  2. https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
  3. https://news.sophos.com/en-us/2020/12/21/how-sunburst-malware-does-defense-evasion/
  4. https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/
  5. https://pastebin.com/6EDgCKxd
  6. https://github.com/fireeye/sunburst_countermeasures
  7. https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware
  8. https://www.fireeye.com/blog/threat-research/2021/03/sunshuttle-second-stage-backdoor-targeting-us-based-entity.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Campaign
SolarWinds Compromise
Actor
UNC3524
Actor
UNC2465
Actor
UNC2659
Actor
UNC2447
Actor
UNC4841
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.