/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Secureworks: a second threat actor targeting SolarWinds flaws, by adding backdoors via Orion bugs, has characteristics that suggest the group is based in China

New Evidence Suggests Potential Links to Chinese Hackers Sean Lyngaas / CyberScoop : China-linked hackers exploited SolarWinds software in 2020 breach, researchers say Pierluigi Paganini / Security Affairs : SUPERNOVA backdoor that emerged after SolarWinds hack is likely linked to Chinese actors Charlie Osborne / ZDNet : Supernova malware clues link Chinese threat group Spiral to SolarWinds server hacks Tweets: Catalin Cimpanu / @campuscodi : These attacks took place in parallel and where unrelated to the broader SolarWinds supply chain attack. The same group was also exploiting Zoho ManageEngine servers. Secureworks didn't say if this was an APT or a classic cybercrime group Report here: https://www.secureworks.com/ ... https://twitter.com/... Catalin Cimpanu / @campuscodi : NEW: In a report today, Secureworks has linked the second threat actor exploiting SolarWinds Orion servers to a Chinese threat actor it calls Spiral This is the group who exploited CVE-2020-10148 (Orion API auth bypass) to install the SUPERNOVA web shell https://therecord.media/... https://twitter.com/...

The Record Catalin Cimpanu

Context & Ripple Effects

When researchers flagged in December 2020 that a second hacking group was inside SolarWinds systems with malware unrelated to Sunburst, the open question was who that actor was and how far its activity reached. Secureworks now answers part of it: the group it tracks as Spiral exploited an Orion API auth bypass (CVE-2020-10148) to plant the SUPERNOVA web shell on Orion servers, in parallel with separate Zoho ManageEngine intrusions.

The attribution matters because it folds into an emerging picture of Chinese activity against SolarWinds' own product line — distinct from the Russian-attributed supply chain operation — including the earlier intrusion into a USDA payroll agency via another SolarWinds bug and Microsoft's later DEV-0322 attribution for Serv-U exploits. Spiral's China-based characteristics make SolarWinds software a product two major state-linked campaigns converged on.

First-order effects

  • Organizations running SolarWinds Orion and Zoho ManageEngine servers must now treat CVE-2020-10148 as an actively exploited vector tied to a named actor, not just a patch-and-move-on vulnerability.
  • Incident responders gain a tracking handle — Spiral — letting them fold SUPERNOVA web shell detections into known Chinese tradecraft rather than investigating each Orion compromise as isolated.

Second-order effects

  • SolarWinds' remediation burden compounds: the company is simultaneously managing fallout from the Sunburst supply chain attack and repeated exploitation of its own management products by a second nation-state actor, pressuring its security posture and customer trust.
  • Other enterprise management-software vendors like Zoho face the same exposure profile — their admin tooling is demonstrably in scope for the same actors, forcing parallel hardening and disclosure work.

Third-order effects

  • If the pattern holds — multiple nation-state groups independently exploiting the same IT-management platforms without coordinating, echoing the finding that three Chinese espionage groups hit Southeast Asian telcos separately — shared infrastructure software becomes a de facto common attack surface requiring vendor-level, not just customer-level, defense.
  • Independent attributions of parallel campaigns push defenders toward hunting across overlapping exploit surfaces rather than single-campaign narratives, reshaping how breach investigations scope 'who else was here' questions.

The trend: Enterprise network-management software is becoming contested ground where multiple nation-state espionage programs operate independently against the same vendors' products.

Discussion

  • @campuscodi Catalin Cimpanu on x
    These attacks took place in parallel and where unrelated to the broader SolarWinds supply chain attack. The same group was also exploiting Zoho ManageEngine servers. Secureworks didn't say if this was an APT or a classic cybercrime group Report here: https://www.secureworks.com/ …
  • @campuscodi Catalin Cimpanu on x
    NEW: In a report today, Secureworks has linked the second threat actor exploiting SolarWinds Orion servers to a Chinese threat actor it calls Spiral This is the group who exploited CVE-2020-10148 (Orion API auth bypass) to install the SUPERNOVA web shell https://therecord.media/.…