Anonymous ID: f5cc54 Dec. 17, 2020, 3:51 p.m. No.12071260   🗄️.is 🔗kun

SOLARWINDS CYBER ATTACK INVOLVES REMOTE ACCESS TROJAN (RAT)

 

This modification included a sophisticated and stealthy Trojan program, designed to remotely control any computer that installed SolarWinds Orion. When customers installed the latest update, the Trojan program would start running on the victims’ computers. This is considered a software “supply chain attack”: The intended victims received a polluted copy of the Orion software directly or indirectly from SolarWinds.

 

What Did the Trojan Do?

 

The Trojan itself was a sophisticated and stealthy backdoor analyzed by both FireEye and Microsoft. Though the program produced some indications to tell if a computer was infected, it first waited 12 to 14 days before taking any action—a period of quiet designed to thwart analysis, as the malicious payload wouldn’t even start until the computer had been running for a long time. Then it started asking for a command-and-control server. Once again, this routine included checks to thwart analysis.