SolarWinds: Trusted updates as a way in
Summary
Brian Krebs describes how manipulated Orion updates carried a supply chain compromise to up to 18,000 customers and enabled prioritised follow-up attacks. SolarWinds named fewer than 18,000 Orion customers that might be affected. According to the analysis at the time, manipulated updates had been distributed since March 2020.
Ideas
- A compromised update channel distributes attacker access through existing trust.
- Network monitoring has particularly far-reaching rights and visibility.
- Initial infection is not the same as a target that is actively exploited.
- Attackers weigh valuable victims against their respective risk of discovery.
- Taking over a command domain can partly switch off malware.
- Official mandatory filings provide measurable limits for early situation reports.
Insights
- Trusted software causes disproportionate damage when it is compromised.
- Supply chain incidents require broad searching and individual prioritisation at the same time.
- A defender can repurpose adversary infrastructure to limit damage.
Quotes
The lawsuits are coming.
– James Lewis
Habits
- Krebs links company filings, technical analyses and current infrastructure changes.
Facts
- Microsoft took over a central command domain of the malware.
References
- Brian Krebs: SolarWinds Hack Could Affect 18K Customers
- SolarWinds Orion: the compromised network management platform.
- FireEye: SUNBURST (technical analysis of the malware).
- CISA: emergency directive to switch off affected products.
Critique
- The article was written during an ongoing incident and therefore contains open questions.
- The figure of 18,000 describes delivered malware, not confirmed follow-up compromises.
Remarks
- SolarWinds made software supply chains a central topic of systems operations.
- Later investigations expanded the known toolchain and choice of victims.
Recommendations
- Treat management systems as particularly sensitive anchors of trust.
- Take central inventory of installed versions and update origins.
- Look for follow-up activity instead of only for the compromised package.
Links to the original source and the Web Archive open in a new tab.