2021-01-12


etc

Solarwinds

  • Solarwind, Fireeye, Microsoft and Cisco leaks are offered for sale | Hacker News

    Washington Post attributed the attack to Russian actor APT29/Cozy Bear on Dec 14th [1], "unnamed gov sources".

    FireEye [2] Dec 13th & Volexity [3] Dec 14th were more cautious, citing an unknown actor dubbed UNC2452, and Dark Halo, respectively.

    Recorded Future made a (fair but ultimately inconclusive) case for Chinese attribution [4], Dec 30th.

    US gov/CISA continues to claim "Russian linked" [5], Jan 5th.

    Kaspersky reported a link to the Kazuar malware used by Russian actor Turla [6], Jan 11th.

    CrowdStrike's report on the malware injector [7], Jan 11th says "does not attribute the SUNSPOT implant, SUNBURST backdoor or TEARDROP post-exploitation tool to any known adversary".

    [1] https://www.washingtonpost.com/national-security/russian-gov... [2] https://www.fireeye.com/blog/threat-research/2020/12/evasive... [3] https://www.volexity.com/blog/2020/12/14/dark-halo-leverages... [4] https://www.recordedfuture.com/solarwinds-attribution/ [5] https://www.cisa.gov/news/2021/01/05/joint-statement-federal... [6] https://securelist.com/sunburst-backdoor-kazuar/99981/ [7] https://www.crowdstrike.com/blog/sunspot-malware-technical-a... -- https://news.ycombinator.com/item?id=25755811

Capitol Insurection

Parler

OrangeManBad

World