Poisoned Installers Found In SolarWinds Hackers Toolkit (securityweek.com) 16
wiredmikey shares a report from SecurityWeek: The ongoing multi-vendor investigations into the SolarWinds mega-hack took another twist this week with the discovery of new malware artifacts that could be used in future supply chain attacks. According to a new report, the latest wave of attacks being attributed to APT29/Nobelium threat actor includes a custom downloader that is part of a "poisoned update installer" for electronic keys used by the Ukrainian government. SentinelOne principal threat researcher Juan Andres Guerrero-Saade documented the latest finding in a blog post that advances previous investigations from Microsoft and Volexity. "At this time, the means of distribution [for the poisoned update installer] are unknown. It's possible that these update archives are being used as part of a regionally-specific supply chain attack," Guerrero-Saade said.
Now are the SolarWinds updates free? or paid (Score:2)
Now are the SolarWinds updates free? or paid to fix the hacked ones?
Re: (Score:2)
Re: (Score:2)
The IT department of my current employer uses SolarWinds Orion.
exe or msi windows installer? (Score:4, Insightful)
Re: (Score:2)
Re:exe or msi windows installer? (Score:5, Informative)
You really have no idea what you're talking about, period.
These installers will only be run by admins.
But they still need to be run on multiple nodes.
Speaking of multiple nodes, when you have a lot of machines, you wind up needing tools to manage them all. It doesn't matter what OS they run.
Tools for Linux can be compromised in exactly the same way as these tools for Windows. So there is zero benefit there, although there are other security benefits to Linux.
Re: (Score:1)
Re: (Score:2)
And why not have multiple levels? You need a highly experienced competent admin to maintain the network overall, but you also need a bunch of lesser paid ones to handle the day to day problems, like fixing a printer, changing a user's password or eve
Re: (Score:2)
Speaking of multiple nodes, when you have a lot of machines, you wind up needing tools to manage them all. It doesn't matter what OS they run.
These tools are for junior admins who need ease of use and give them full access so the company can hire cheaper users. Domain Admins already have many ways to monitor systems with existing tools. Experienced admins can already do a lot of the things that these tools do, just not in a GUI.
Paying for an experienced admin that knows command line scripting, has a larger recurring cost. Tools such as Solarwinds Orion has a cheaper recurring cost, so you can hire more junior admins for more "coverage".
Re: (Score:1)
Yea but then you'd have to hire someone actually literate to do your government IT jobs, and those guys are so expensive they cut into the budget for our autonomous peasant killers.
Re: (Score:2)
The word you were looking for was killbot [theinfosphere.org].
1: Hack the installer ... (Score:2)
1: Hack the installer of component X to also install ransomware (set to go off on trigger or timer) and/or other persistent threats.
2: Attack a system with ransomware installed by some other vector via a vulnerability in component X.
3: Profit.
4: News of the attack of 2: is published.
5: EVERYBODY downloads the next update of component X.
6: Pick a bunch of deep-pocket targets and have at them.
7: P*R*O*F*I*T!
8: Rinse and repeat.
I normally make the "Hackers are the cowboys, Crackers are the cattle-rustlers (who