Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BRONZE SPIRAL

Description

In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platform software to deploy a web shell dubbed SUPERNOVA. CTU researchers track the operators of the SUPERNOVA web shell as BRONZE SPIRAL and assess with low confidence that the group is of Chinese origin. SUPERNOVA was likely deployed through exploitation of CVE-2020-10148, and CTU researchers observed post-exploitation reconnaissance commands roughly 30 minutes before the web shell was deployed. This may have been indicative of the threat actor conducting scan-and-exploit activity and then triaging for victims of particular interest, before deploying SUPERNOVA and attempting to dump credentials and move laterally. BRONZE SPIRAL has been associated with previous intrusions involving the targeting of ManageEngine servers, maintenance of long-term access to periodically harvest credentials and exfiltrate data, and espionage or theft of intellectual property. The threat group makes extensive use of native system tools and 'living off the land' techniques.

AI Analysis

· 2 weeks ago

Executive Summary

BRONZE SPIRAL is an unidentified threat actor believed with low confidence to be of Chinese origin. The group targeted SolarWinds through a vulnerability in their Orion Platform, deploying a web shell named SUPERNOVA. BRONZE SPIRAL's activities include long-term access to victim networks for credential harvesting and data exfiltration, likely focusing on espionage or intellectual property theft.

Goals & Targeting

BRONZE SPIRAL's strategic objectives appear to focus on espionage or theft of intellectual property, likely targeting sectors with significant technological or sensitive information, such as government entities, defense contractors, and telecommunications companies. The group's observed behavior suggests they prioritize high-value victims that provide access to valuable data or infrastructure. Their operational focus on IT management software providers like SolarWinds and ManageEngine indicates a sector-specific targeting approach.

Enhanced Description

BRONZE SPIRAL emerged into public view following the December 2020 SolarWinds attack. The threat group exploited a vulnerability (CVE-2020-10148) in SolarWinds' Orion Platform to deploy SUPERNOVA, a web shell. CTU researchers observed pre-deployment reconnaissance activity, suggesting the actors conducted targeted scanning and triaging of victims before full deployment. In addition to SolarWinds, BRONZE SPIRAL has been linked to intrusions involving ManageEngine servers. The group is known for maintaining persistent access to victim networks over extended periods, periodically harvesting credentials, and exfiltrating sensitive data. Their primary activities appear to align with espionage or intellectual property theft objectives. BRONZE SPIRAL's operational tactics include extensive use of native system tools and 'living off the land' techniques, making their activity difficult to detect. The group's ability to maintain long-term access and adapt their methods underscores a level of technical proficiency.

Key Capabilities

  • Web shell deployment
  • 'Living off the land' techniques
  • Credential dumping
  • Lateral movement within networks
  • Data exfiltration
  • Long-term persistence

MITRE ATT&CK Tactics

Intrusion Toolkit
Collection
Lateral Movement

ATT&CK Techniques

T1058.002 - Application Window Stealing
T1093.001 - OS Credential Dumping: Registry
T1510.004 - Exfiltration Over Alternative Protocols
T1574 - Data Destruction
T1566.002 - Pass the Hash

Software / Tooling

SUPERNOVA Web Shell
SolarWinds Orion Platform Exploit (CVE-2020-10148)
Native system tools

Campaigns & Victims

BRONZE SPIRAL's campaign patterns suggest a focus on targeted attacks with long-term operational persistence. Known campaigns include the December 2020 SolarWinds attack and intrusions involving ManageEngine servers. The group demonstrates patient hunting behavior, scanning for high-value targets before deploying SUPERNOVA and establishing persistence. Notable operations involve credential dumping, lateral movement, and prolonged data exfiltration efforts.

IOC Patterns

  • Exploitation attempts targeting CVE-2020-10148
  • Web shell activity indicative of SUPERNOVA deployment
  • Unusual system administrator account activity
  • Registry modifications related to credential dumping
  • Scheduled task creation for persistence

Recommended Actions

  • Patch all known vulnerabilities in SolarWinds Orion Platform and other IT management software.
  • Monitor for unusual activity indicative of web shell deployments or 'living off the land' tactics.
  • Implement multi-factor authentication for high-value accounts to mitigate credential dumping risks.
  • Conduct regular network traffic analysis to detect data exfiltration activities.
  • Enhance logging and monitoring of system administrator tools and their usage patterns.

Suggested Tags

State-sponsored
Advanced Persistent Threat (APT)
Espionage
IT Management Software

Confidence Assessment

Low confidence in BRONZE SPIRAL's origin and exact objectives due to limited公开 attribution. More intelligence is needed to fully understand the group's capabilities, campaign history, and specific tools.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Supply Chain Attack
Backdoor / C2
State-sponsored
Advanced Persistent Threat (APT)
Espionage
IT Management Software

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.