bk99.de entertain the web since 1997

SolarWinds: Trusted updates as a way in

Summary

Brian Krebs describes how manipulated Orion updates carried a supply chain compromise to up to 18,000 customers and enabled prioritised follow-up attacks. SolarWinds named fewer than 18,000 Orion customers that might be affected. According to the analysis at the time, manipulated updates had been distributed since March 2020.

Ideas

  • A compromised update channel distributes attacker access through existing trust.
  • Network monitoring has particularly far-reaching rights and visibility.
  • Initial infection is not the same as a target that is actively exploited.
  • Attackers weigh valuable victims against their respective risk of discovery.
  • Taking over a command domain can partly switch off malware.
  • Official mandatory filings provide measurable limits for early situation reports.

Insights

  • Trusted software causes disproportionate damage when it is compromised.
  • Supply chain incidents require broad searching and individual prioritisation at the same time.
  • A defender can repurpose adversary infrastructure to limit damage.

Quotes

  • The lawsuits are coming. – James Lewis

Habits

  • Krebs links company filings, technical analyses and current infrastructure changes.

Facts

  • Microsoft took over a central command domain of the malware.

References

Critique

  • The article was written during an ongoing incident and therefore contains open questions.
  • The figure of 18,000 describes delivered malware, not confirmed follow-up compromises.

Remarks

  • SolarWinds made software supply chains a central topic of systems operations.
  • Later investigations expanded the known toolchain and choice of victims.

Recommendations

  • Treat management systems as particularly sensitive anchors of trust.
  • Take central inventory of installed versions and update origins.
  • Look for follow-up activity instead of only for the compromised package.

Read the original article

Search the Web Archive