Security News > 2021 > January > SolarWinds hackers used 7-Zip code to hide Raindrop Cobalt Strike loader

SolarWinds hackers used 7-Zip code to hide Raindrop Cobalt Strike loader
2021-01-19 14:09

The ongoing analysis of the SolarWinds supply-chain attack uncovered a fourth malicious tool that researchers call Raindrop and was used for distribution across computers on the victim network.

The hackers used Raindrop to deliver a Cobalt Strike beacon to select victims that were of interest and which had already been compromised through the trojanized SolarWinds Orion update.

Symantec researchers found the new Raindrop malware on machines compromised through the SolarWinds cyberattack.

To hide the malicious functionality, the hackers used a modified version of the 7-Zip source code to compile Raindrop as a DLL file.

Cybersecurity company Volexity investigating SolarWinds cyberattacks also reported that the hackers used PowerShell for lateral movement activity by creating new tasks on remote machines.

Symantec finding Raindrop adds another piece to the SolarWinds supply-chain attack puzzle.


News URL

https://www.bleepingcomputer.com/news/security/solarwinds-hackers-used-7-zip-code-to-hide-raindrop-cobalt-strike-loader/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Solarwinds 56 33 104 80 50 267
7 ZIP 2 0 6 6 1 13