SUNBURST is the malware that was distributed through SolarWinds software. As part of our analysis of SUNBURST, we identified a killswitch that would prevent SUNBURST from continuing to operate. 2/5
Depending on the IP address returned when the malware resolves avsvmcloud[.]com, under certain conditions, the malware would terminate itself and prevent further execution. We’ve collaborated with @GoDaddy and @Microsoft to deactivate SUNBURST infections. 3/5
This killswitch will affect new & previous SUNBURST infections by disabling SUNBURST deployments that are still beaconing to avsvmcloud[.]com. However, this actor moved quickly to establish additional persistent mechanisms to access victim networks beyond SUNBURST backdoor. 4/5
This killswitch will not remove the actor from victim networks where they have established other backdoors. However, it will make it more difficult for the actor to leverage the previously distributed versions of SUNBURST. 5/5
You can follow @FireEye.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.