SUPERNOVA activity and its possible connection to SPIRAL threat group. episode artwork

EPISODE · May 8, 2021 · 20 MIN

SUPERNOVA activity and its possible connection to SPIRAL threat group.

from Research Saturday · host N2K Networks

Guest Mike McLellan from Secureworks joins us to share his team's insights about SUPERNOVA and threat group attribution. Similarities between the SUPERNOVA activity and a previous compromise of the network suggest that SPIRAL was responsible for both intrusions and reveal information about the threat group. In late 2020, Secureworks® Counter Threat Unit™ (CTU) researchers observed a threat actor exploiting an internet-facing SolarWinds server to deploy the SUPERNOVA web shell. Additional analysis revealed similarities to intrusion activity identified on the same network earlier in 2020, suggesting the two intrusions are linked. CTU™ researchers attribute the intrusions to the SPIRAL threat group. Characteristics of the activity suggest the group is based in China. The research can be found here: SUPERNOVA Web Shell Deployment Linked to SPIRAL Threat Group

Episode metadata supplied by the publisher feed · Published May 8, 2021

Embed this episode

NOW PLAYING

SUPERNOVA activity and its possible connection to SPIRAL threat group.

0:00 20:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Research Saturday?

This episode is 20 minutes long.

When was this Research Saturday episode published?

This episode was published on May 8, 2021.

Can I download this Research Saturday episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!