SolarStorm

Threat Actor updated 23 days ago (2024-10-04T23:00:58.444Z)
Download STIX
Preview STIX
SolarStorm is a threat actor known for its execution of actions with malicious intent, as evidenced by its involvement in software supply-chain attacks. This group, also tracked under different names such as APT29, UNC3524, NobleBaron, Dark Halo, NOBELIUM, Cozy Bear, and CozyDuke, has been particularly active in targeting embassy entities using various lures, including BMW car sales. The cybersecurity industry recognizes SolarStorm for its tactical and persistent methods of operation throughout the entire attack cycle. In 2020, SolarStorm was implicated in a significant attack on SolarWinds Orion software, demonstrating their capacity to compromise and manipulate software supply chains. In March, a similar attack was discovered targeting 3CX, a voice over IP (VOIP) solution. In this instance, unknown malicious actors tampered with a software update for the 3CXDesktopApp, resulting in malware being served to the company's customer base. These incidents highlight the sophisticated nature of SolarStorm's operations and the potential risks they pose to digital infrastructure. However, there are some uncertainties regarding SolarStorm's activities. For example, the association between the SUPERNOVA webshell and the SolarStorm actors is questionable due to differences in digital signatures. Furthermore, while it is clear that SolarStorm is capable of utilizing various techniques to accomplish their goals, details on initial access vectors beyond the compromised SolarStorm software have not yet been confirmed. As new information emerges, Palo Alto Networks continues to monitor and protect against this threat, updating their Threat Brief on SolarStorm and SUNBURST accordingly.
Description last updated: 2024-10-04T22:16:35.421Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the SolarStorm Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more