| Washington Post attributed the attack to Russian actor APT29/Cozy Bear on Dec 14th [1], quoting unnamed sources. FireEye [2] Dec 13th & Volexity [3] Dec 14th were more cautious, citing an unknown actor that they dubbed UNC2452, and Dark Halo, respectively. Recorded Future made a fair but ultimately inconclusive case for Chinese attribution [4], Dec 30th. US gov/CISA continues to claim "Russian linked" [5], Jan 5th. Kaspersky reported a link to the Kazuar malware used by Russian actor Turla [6], Jan 11th. CrowdStrike's report on the malware injector [7], Jan 11th says "does not attribute the SUNSPOT implant, SUNBURST backdoor or TEARDROP post-exploitation tool to any known adversary". [1] https://www.washingtonpost.com/national-security/russian-gov... [2] https://www.fireeye.com/blog/threat-research/2020/12/evasive... [3] https://www.volexity.com/blog/2020/12/14/dark-halo-leverages... [4] https://www.recordedfuture.com/solarwinds-attribution/ [5] https://www.cisa.gov/news/2021/01/05/joint-statement-federal... [6] https://securelist.com/sunburst-backdoor-kazuar/99981/ [7] https://www.crowdstrike.com/blog/sunspot-malware-technical-a... |