BRONZE SPIRAL is a threat actor likely of Chinese origin, known for targeting SolarWinds Orion software.
Analyst brief
BRONZE SPIRAL is a threat actor assessed with low confidence to be of Chinese origin. It targets organizations using SolarWinds Orion Platform software, particularly for initial access through exploitation. Key TTPs include exploiting CVE-2020-10148 to deploy the SUPERNOVA web shell and conducting scan-and-exploit activity with pre-deployment reconnaissance. Defenders should focus on detecting SUPERNOVA web shell artifacts in SolarWinds Orion instances and monitoring for exploitation attempts against this software.
BRONZE SPIRAL
unknown
In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platform software to deploy a web shell dubbed SUPERNOVA. CTU researchers track the operators of the SUPERNOVA web shell as BRONZE SPIRAL and assess with low confidence that the group is of Chinese origin. SUPERNOVA was likely deployed through exploitation of CVE-2020-10148, and CTU researchers observed post-exploitation reconnaissance commands roughly 30 minutes before the web shell was deployed. This may have been indicative of the threat actor conducting scan-and-exploit activity and then triaging for victims of particular interest, before deploying SUPERNOVA and attempting to dump credentials and move laterally.
BRONZE SPIRAL has been associated with previous intrusions involving the targeting of ManageEngine servers, maintenance of long-term access to periodically harvest credentials and exfiltrate data, and espionage or theft of intellectual property. The threat group makes extensive use of native system tools and 'living off the land' techniques.