SolarWinds SUNBURST 供应链攻击
2020 年国家支持的 SolarWinds Orion 供应链失陷事件,通过受信任的软件更新将 SUNBURST 后门植入数千家组织。
来源归属
- 来源类型
- Vendor advisory
- 来源
- CISA · Microsoft · Mandiant
- 置信度
- high
Source: CISA · Microsoft · Mandiant · Confidence: high
安全时间线
- published Orion platform compromise begins (approx.)
- exploited SUNBURST trojanized updates delivered via Orion
- updated FireEye discloses; CISA issues emergency directive 21-01
快速解答
SolarWinds 攻击活动(2020)利用被植入木马的 SolarWinds Orion 更新,将 SUNBURST 后门投递到超过 18,000 家组织,并在美国政府、科技公司和安全公司网络中观察到后续访问活动。
定义
供应链入侵事件:SolarWinds Orion 构建环境被攻陷,在签名软件更新中植入恶意代码;SUNBURST 后门使用 DNS 和 HTTP 命令与控制(C2)通信,并借助基于休眠的限速规避检测。
防御经验:核验软件构建完整性、隔离更新管道,并将来自受信任厂商的签名二进制视为残余供应链风险面。