Case Study - Supply Chain Attack

SolarWinds Attack

Year – 2020

Estimated Economic LossesUS$100 Million+ in investigation, remediation, recovery, and security improvement costs.

Systems Affected -Approximately 18,000 organizations downloaded the compromised software update

Type of Attack – Software Supply Chain Attack | Cyber Espionage Campaign

Suspected Group / Organization – Associated with APT29 (Cozy Bear) and attributed by the U.S. government to Russia’s Foreign Intelligence Service (SVR)

Detailed Working
Attackers compromised the SolarWinds Orion software build environment and inserted the SUNBURST backdoor into legitimate software updates. Organizations that installed the compromised updates unknowingly provided attackers with initial access, allowing them to conduct reconnaissance, establish persistence, move laterally, and access sensitive systems and information.

Forensic Investigations
Investigators used malware reverse engineering, network traffic analysis, system and authentication log examination, and cloud forensics to analyze the attack. The investigation identified compromised Orion updates, SUNBURST malware artifacts, command-and-control communications, unauthorized account activity, and lateral movement, while threat intelligence and infrastructure analysis contributed to the attack’s attribution.

+91-7087055115

sales@ryuzasecurity.com

Subscribe Now.

No content is added yet.