UNC2452 is a Russia-linked threat actor known for the SolarWinds supply chain compromise targeting government entities.
Analyst brief
UNC2452 (Midnight Blizzard) is a Russia-originated cyber threat group. It primarily targets high-profile organizations, including government entities, through the SolarWinds software supply chain injection. The group leverages SUNBURST, TEARDROP malware and C2 infrastructure for long-term reconnaissance and lateral movement. Defenders must focus on software supply chain security, anomalous authentication attempts, and suspicious lateral movement activities.
UNC2452
DarkHaloStellarParticleNOBELIUM
activeunknown
Reporting regarding activity related to the SolarWinds supply chain injection has grown quickly since initial disclosure on 13 December 2020. A significant amount of press reporting has focused on the identification of the actor(s) involved, victim organizations, possible campaign timeline, and potential impact. The US Government and cyber community have also provided detailed information on how the campaign was likely conducted and some of the malware used. MITRE’s ATT&CK team — with the assistance of contributors — has been mapping techniques used by the actor group, referred to as UNC2452/Dark Halo by FireEye and Volexity respectively, as well as SUNBURST and TEARDROP malware.