SUPERNOVA

S0578

Malware.View on attack.mitre.org

About this malware

SUPERNOVA is an in-memory web shell written in .NET C#. It was discovered in November 2020 during the investigation of APT29's SolarWinds cyber operation but determined to be unrelated. Subsequent analysis suggests SUPERNOVA may have been used by the China-based threat group SPIRAL.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

SUPERNOVA contained Base64-encoded strings.

T1036.005
Match Legitimate Resource Name or Location

SUPERNOVA has masqueraded as a legitimate SolarWinds DLL.

T1071.001
Web Protocols

SUPERNOVA had to receive an HTTP GET request containing a specific set of parameters in order to execute.

T1203
Exploitation for Client Execution

SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148).

T1505.003
Web Shell

SUPERNOVA is a Web shell.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. CISA Supernova Jan 2021 Open source
    CISA. (2021, January 27). Malware Analysis Report (AR21-027A). Retrieved February 22, 2021.
  2. Guidepoint SUPERNOVA Dec 2020 Open source
    Riley, W. (2020, December 1). SUPERNOVA SolarWinds .NET Webshell Analysis. Retrieved February 18, 2021.
  3. Microsoft Analyzing Solorigate Dec 2020 Open source
    MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.
  4. SolarWinds Advisory Dec 2020 Open source
    SolarWinds. (2020, December 24). SolarWinds Security Advisory. Retrieved February 22, 2021.
  5. Unit42 SUPERNOVA Dec 2020 Open source
    Tennis, M. (2020, December 17). SUPERNOVA: A Novel .NET Webshell. Retrieved February 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.