Team A and Team B: Sunburst, Teardrop and Raindrop
The other day Microsoft published a great deep dive around the second stage payloads and hands-on hacking activities of the Solarwinds/Sunburst incidents that where uncovered late 2020.
One thing that is so interesting is the use of off the shelve Cobalt Strike tooling and templates for command & control. After doing all the hard work and customization to seamlessly backdoor binaries the adversaries sem to use Cobalt Strike.
Intel for Red TeamersAlthough, they did add customizations with some interesting features, which are interesting for red teamers to be aware of. For instance each instance of the zombie would be unique in name, folder locations, etc. to make it more difficult to identify in environments.