In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platform software to deploy a web shell dubbed SUPERNOVA. CTU researchers track the operators of the SUPERNOVA web shell as BRONZE SPIRAL and assess with low confidence that the group is of Chinese origin. SUPERNOVA was likely deployed through exploitation of CVE-2020-10148, and CTU researchers observed post-exploitation reconnaissance commands roughly 30 minutes before the web shell was deployed. This may have been indicative of the threat actor conducting scan-and-exploit activity and then triaging for victims of particular interest, before deploying SUPERNOVA and attempting to dump credentials and move laterally. BRONZE SPIRAL has been associated with previous intrusions involving the targeting of ManageEngine servers, maintenance of long-term access to periodically harvest credentials and exfiltrate data, and espionage or theft of intellectual property. The threat group makes extensive use of native system tools and 'living off the land' techniques.
Executive Summary
BRONZE SPIRAL is an unidentified threat actor believed with low confidence to be of Chinese origin. The group targeted SolarWinds through a vulnerability in their Orion Platform, deploying a web shell named SUPERNOVA. BRONZE SPIRAL's activities include long-term access to victim networks for credential harvesting and data exfiltration, likely focusing on espionage or intellectual property theft.
Goals & Targeting
BRONZE SPIRAL's strategic objectives appear to focus on espionage or theft of intellectual property, likely targeting sectors with significant technological or sensitive information, such as government entities, defense contractors, and telecommunications companies. The group's observed behavior suggests they prioritize high-value victims that provide access to valuable data or infrastructure. Their operational focus on IT management software providers like SolarWinds and ManageEngine indicates a sector-specific targeting approach.
Enhanced Description
BRONZE SPIRAL emerged into public view following the December 2020 SolarWinds attack. The threat group exploited a vulnerability (CVE-2020-10148) in SolarWinds' Orion Platform to deploy SUPERNOVA, a web shell. CTU researchers observed pre-deployment reconnaissance activity, suggesting the actors conducted targeted scanning and triaging of victims before full deployment. In addition to SolarWinds, BRONZE SPIRAL has been linked to intrusions involving ManageEngine servers. The group is known for maintaining persistent access to victim networks over extended periods, periodically harvesting credentials, and exfiltrating sensitive data. Their primary activities appear to align with espionage or intellectual property theft objectives. BRONZE SPIRAL's operational tactics include extensive use of native system tools and 'living off the land' techniques, making their activity difficult to detect. The group's ability to maintain long-term access and adapt their methods underscores a level of technical proficiency.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BRONZE SPIRAL's campaign patterns suggest a focus on targeted attacks with long-term operational persistence. Known campaigns include the December 2020 SolarWinds attack and intrusions involving ManageEngine servers. The group demonstrates patient hunting behavior, scanning for high-value targets before deploying SUPERNOVA and establishing persistence. Notable operations involve credential dumping, lateral movement, and prolonged data exfiltration efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in BRONZE SPIRAL's origin and exact objectives due to limited公开 attribution. More intelligence is needed to fully understand the group's capabilities, campaign history, and specific tools.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics