FireEye Identifies Killswitch for SolarWinds ...
FireEye on Sunday said that an investigation it was conducting into a breach of its own network last week uncovered a threat actor widely distributing a backdoor dubbed SUNBURST by hiding it in legitimate updates of SolarWinds Orion network management technology. SUNBURST (SolarWinds.Orion.Core.BusinessLayer dot dll) is a sort of first-stage Trojan that the attackers were using to drop additional payloads for escalating privileges, lateral movement, and data theft on infected networks, FireEye�...
Solarwind Orion Daniel Trauner Solarwinds Orion White House National Security Council Coordination Group Infrastructure Security Agency
Source: darkreading.com