CrowdStrike Intelligence Team. (2021, January 11). SUNSPOT: An Implant in the Build Process. Retrieved January 11, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareSUNSPOT | SUNSPOT encrypted log entries it collected with the stream cipher RC4 using a hard-coded key. It also uses AES128-CBC encrypted blobs for SUNBURST source code and data extracted from the SolarWinds Orion <MsBuild.exe</code> process. |
| T1027.005 Indicator Removal from Tools |
MalwareSUNBURST | SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNSPOT | SUNSPOT was identified on disk with a filename of |
| T1053.005 Scheduled Task |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `scheduler` and `schtasks` to create new tasks on remote host as part of their lateral movement. They manipulated scheduled tasks by updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration. APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted. |
| T1057 Process Discovery |
MalwareSUNSPOT | SUNSPOT monitored running processes for instances of |
| T1070.004 File Deletion |
MalwareSUNSPOT | Following the successful injection of SUNBURST, SUNSPOT deleted a temporary file it created named |
| T1083 File and Directory Discovery |
MalwareSUNSPOT | SUNSPOT enumerated the Orion software Visual Studio solution directory path. |
| T1106 Native API |
MalwareSUNSPOT | SUNSPOT used Windows API functions such as |
| T1134 Access Token Manipulation |
MalwareSUNSPOT | SUNSPOT modified its security token to grants itself debugging privileges by adding |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSUNSPOT | SUNSPOT decrypts SUNBURST, which was stored in AES128-CBC encrypted blobs. |
| T1195.002 Compromise Software Supply Chain |
MalwareSUNSPOT | SUNSPOT malware was designed and used to insert SUNBURST into software builds of the SolarWinds Orion IT management product. |
| T1480 Execution Guardrails |
MalwareSUNSPOT | SUNSPOT only replaces SolarWinds Orion source code if the MD5 checksums of both the original source code file and backdoored replacement source code match hardcoded values. |
| T1480.002 Mutual Exclusion |
MalwareSUNSPOT | SUNSPOT creates a mutex using the hard-coded value ` {12d61a41-4b74-7610-a4d8-3028d2f56395}` to ensure that only one instance of itself is running. |
| T1565.001 Stored Data Manipulation |
MalwareSUNSPOT | SUNSPOT created a copy of the SolarWinds Orion software source file with a |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.