Posts

Showing posts with the label #phishing

How to hack Solar wind ?

Image
     A malicious web shell deployed on Windows systems by leveraging a previously undisclosed zero-day in Solar Winds' Orion network monitoring software may have been the work of a possible Chinese threat group.       In a report published by Secure works on Monday, the cyber security firm attributed the intrusions to a threat actor it calls Spiral.       Back on December 22, 2020, Microsoft disclosed that a second   espionage group may have been abusing the IT infrastructure provider's Orion software to drop a persistent backdoor called Supernova on target systems. The findings were also corroborated by cyber security firms Palo Alto Networks' Unit 42 threat intelligence team and GuidePoint Security, both of whom described Supernova as a .NET web shell implemented by modifying an "app_web_logoimagehandler.ashx.b6031896.dll" module of the SolarWinds Orion application. What is role of  CTU Researchers ? According to Secure work...