Security News > 2020 > December > Microsoft: SolarWinds hackers' goal was the victims' cloud data

Microsoft: SolarWinds hackers' goal was the victims' cloud data
2020-12-29 13:30

Microsoft says that the end goal of the SolarWinds supply chain compromise was to pivot to the victims' cloud assets after deploying the Sunburst/Solorigate backdoor on their local networks.

As the Microsoft 365 Defender Team explains, after infiltrating a target's network with the help of the Sunburst backdoor, the attackers' goal is to gain access to the victims' cloud assets.

Microsoft's previous articles on the SolarWinds supply chain attack and National Security Agency guidance also hinted at the fact that the attackers' ultimate goal was to generate SAML tokens to forge authentication tokens allowing access to cloud resources.

Using attacker-created SAML tokens to access cloud resources and perform actions leading to the exfiltration of emails and persistence in the cloud.

In its guidance highlighting SolarWinds hackers' TTPs for pivoting to cloud resources, the NSA also shared mitigation measures against unauthorized cloud access which require making it difficult for threat actors to gain access to on-premise identity and federation services.


News URL

https://www.bleepingcomputer.com/news/security/microsoft-solarwinds-hackers-goal-was-the-victims-cloud-data/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Solarwinds 56 33 102 81 51 267