ATT&CKReferencesMicrosoft Analyzing Solorigate Dec 2020

Microsoft Analyzing Solorigate Dec 2020

MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples13

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSUNBURST

SUNBURST collected information from a compromised host.

T1027.015
Compression
MalwareSUNBURST

SUNBURST strings were compressed and encoded in Base64.

T1033
System Owner/User Discovery
MalwareSUNBURST

SUNBURST collected the username from a compromised host.

T1036.005
Match Legitimate Resource Name or Location
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign.

T1059.001
PowerShell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

T1059.003
Windows Command Shell
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines.

T1070.004
File Deletion
MalwareSUNBURST

SUNBURST had a command to delete files.

T1082
System Information Discovery
MalwareSUNBURST

SUNBURST collected hostname and OS version.

T1083
File and Directory Discovery
MalwareSUNBURST

SUNBURST had commands to enumerate files and directories.

T1112
Modify Registry
MalwareSUNBURST

SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their HKLM\SYSTEM\CurrentControlSet\services\\[service_name]\\Start registry entries to value 4. It also deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.

T1124
System Time Discovery
MalwareSUNBURST

SUNBURST collected device `UPTIME`.

T1497.001
System Checks
MalwareSUNBURST

SUNBURST checked the domain name of the compromised host to verify it was running in a real environment.

T1518.001
Security Software Discovery
MalwareSUNBURST

SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.