Threat actor
UNC2452
Last fetched
UNC2452 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 66 techniques and also known as 5 other names.
Also known as
DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix, Midnight Blizzard
Description
Reporting regarding activity related to the SolarWinds supply chain injection has grown quickly since initial disclosure on 13 December 2020. A significant amount of press reporting has focused on the identification of the actor(s) involved, victim organizations, possible campaign timeline, and potential impact. The US Government and cyber community have also provided detailed information on how the campaign was likely conducted and some of the malware used. MITRE’s ATT&CK team — with the assistance of contributors — has been mapping techniques used by the actor group, referred to as UNC2452/Dark Halo by FireEye and Volexity respectively, as well as SUNBURST and TEARDROP malware.
Techniques by tactic
Persistence
- T1037 · Boot or Logon Initialization Scripts
- T1037.004 · RC Scripts
- T1053.005 · Scheduled Task
- T1078 · Valid Accounts
- T1078.003 · Local Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1098.005 · Device Registration
- T1133 · External Remote Services
- T1136.003 · Cloud Account
- T1505.003 · Web Shell
- T1546.003 · Windows Management Instrumentation Event Subscription
- T1546.008 · Accessibility Features
- T1547.001 · Registry Run Keys / Startup Folder
- T1556.007 · Hybrid Identity
Privilege Escalation
- T1037 · Boot or Logon Initialization Scripts
- T1037.004 · RC Scripts
- T1053.005 · Scheduled Task
- T1068 · Exploitation for Privilege Escalation
- T1078 · Valid Accounts
- T1078.003 · Local Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1098.005 · Device Registration
- T1546.003 · Windows Management Instrumentation Event Subscription
- T1546.008 · Accessibility Features
- T1547.001 · Registry Run Keys / Startup Folder
- T1548.002 · Bypass User Account Control
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to UNC2452 today — this states the absence of a published link, not that UNC2452 has no infrastructure.
References
- https://medium.com/mitre-attack/identifying-unc2452-related-techniques-9f7b6c7f3714
- https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
- https://news.sophos.com/en-us/2020/12/21/how-sunburst-malware-does-defense-evasion/
- https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/
- https://pastebin.com/6EDgCKxd
- https://github.com/fireeye/sunburst_countermeasures
- https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware
- https://www.fireeye.com/blog/threat-research/2021/03/sunshuttle-second-stage-backdoor-targeting-us-based-entity.html
- https://unit42.paloaltonetworks.com/atoms/solarphoenix/
- https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/
- https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from UNC2452 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.