Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process. |
| T1036.005 Match Legitimate Resource Name or Location |
SUNSPOT was identified on disk with a filename of |
| T1057 Process Discovery |
SUNSPOT monitored running processes for instances of |
| T1070.004 File Deletion |
Following the successful injection of SUNBURST, SUNSPOT deleted a temporary file it created named |
| T1083 File and Directory Discovery |
SUNSPOT enumerated the Orion software Visual Studio solution directory path. |
| T1106 Native API |
SUNSPOT used Windows API functions such as |
| T1134 Access Token Manipulation |
SUNSPOT modified its security token to grants itself debugging privileges by adding |
| T1140 Deobfuscate/Decode Files or Information |
SUNSPOT decrypts SUNBURST, which was stored in AES128-CBC encrypted blobs. |
| T1195.002 Compromise Software Supply Chain |
SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product. |
| T1480 Execution Guardrails |
SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values. |
| T1480.002 Mutual Exclusion |
SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running. |
| T1565.001 Stored Data Manipulation |
SUNSPOT created a copy of the SolarWinds Orion software source file with a |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.