Skip to content
By using Twitter’s services you agree to our Cookies Use. We and our partners operate globally and use cookies, including for analytics, personalisation, and ads.
  • Home Home Home, current page.
  • About

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @
  • Language: English
    • Bahasa Indonesia
    • Bahasa Melayu
    • Català
    • Čeština
    • Dansk
    • Deutsch
    • English UK
    • Español
    • Filipino
    • Français
    • Hrvatski
    • Italiano
    • Magyar
    • Nederlands
    • Norsk
    • Polski
    • Português
    • Română
    • Slovenčina
    • Suomi
    • Svenska
    • Tiếng Việt
    • Türkçe
    • Ελληνικά
    • Български език
    • Русский
    • Српски
    • Українська мова
    • עִבְרִית
    • العربية
    • فارسی
    • मराठी
    • हिन्दी
    • বাংলা
    • ગુજરાતી
    • தமிழ்
    • ಕನ್ನಡ
    • ภาษาไทย
    • 한국어
    • 日本語
    • 简体中文
    • 繁體中文
  • Have an account? Log in
    Have an account?
    · Forgot password?

    New to Twitter?
    Sign up
KimZetter's profile
Kim Zetter
Kim Zetter
Kim Zetter
Verified account
@KimZetter

Tweets

Kim ZetterVerified account

@KimZetter

Journalist - cybersecurity/national security. Author of COUNTDOWN TO ZERO DAY: Stuxnet and the Launch of the World's First Digital Weapon. Speaker. Signal user

San Francisco
amazon.com/Countdown-Zero…
Joined June 2009

Tweets

  • © 2020 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Dismiss
Previous
Next

Go to a person's profile

Saved searches

  • Remove
  • In this conversation
    Verified accountProtected Tweets @
Suggested users
  • Verified accountProtected Tweets @
  • Verified accountProtected Tweets @

Promote this Tweet

Block

  • Tweet with a location

    You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more

    Your lists

    Create a new list


    Under 100 characters, optional

    Privacy

    Copy link to Tweet

    Embed this Tweet

    Embed this Video

    Add this Tweet to your website by copying the code below. Learn more

    Add this video to your website by copying the code below. Learn more

    Hmm, there was a problem reaching the server.

    By embedding Twitter content in your website or app, you are agreeing to the Twitter Developer Agreement and Developer Policy.

    Preview

    Why you're seeing this ad

    Log in to Twitter

    · Forgot password?
    Don't have an account? Sign up »

    Sign up for Twitter

    Not on Twitter? Sign up, tune into the things you care about, and get updates as they happen.

    Sign up
    Have an account? Log in »

    Two-way (sending and receiving) short codes:

    Country Code For customers of
    United States 40404 (any)
    Canada 21212 (any)
    United Kingdom 86444 Vodafone, Orange, 3, O2
    Brazil 40404 Nextel, TIM
    Haiti 40404 Digicel, Voila
    Ireland 51210 Vodafone, O2
    India 53000 Bharti Airtel, Videocon, Reliance
    Indonesia 89887 AXIS, 3, Telkomsel, Indosat, XL Axiata
    Italy 4880804 Wind
    3424486444 Vodafone
    » See SMS short codes for other countries

    Confirmation

     

    Welcome home!

    This timeline is where you’ll spend most of your time, getting instant updates about what matters to you.

    Tweets not working for you?

    Hover over the profile pic and click the Following button to unfollow any account.

    Say a lot with a little

    When you see a Tweet you love, tap the heart — it lets the person who wrote it know you shared the love.

    Spread the word

    The fastest way to share someone else’s Tweet with your followers is with a Retweet. Tap the icon to send it instantly.

    Join the conversation

    Add your thoughts about any Tweet with a Reply. Find a topic you’re passionate about, and jump right in.

    Learn the latest

    Get instant insight into what people are talking about now.

    Get more of what you love

    Follow more accounts to get instant updates about topics you care about.

    Find what's happening

    See the latest conversations about any topic instantly.

    Never miss a Moment

    Catch up instantly on the best stories happening as they unfold.

    Kim Zetter‏Verified account @KimZetter Dec 13

    I have report from Microsoft about SolarWinds hack, including IoCs. Excerpts in this thread: "Microsoft security researchers recently discovered a sophisticated attack where an adversary inserted malicious code into a supply chain development process.... 1/

    6:09 PM - 13 Dec 2020
    • 1,393 Retweets
    • 3,202 Likes
    • Lucian Corlan Madeleine Kaur Tilly Collins WithU Claudeen Denning Renate Satler Mohamed Mostafa CalhounCountyDemocratsGOTV Bryan Priest
    69 replies 1,393 retweets 3,202 likes
      1. New conversation
      2. Kim Zetter‏Verified account @KimZetter Dec 13

        "A malicious software class was included among many other legitimate classes and then signed with a legitimate certificate. The resulting binary included a backdoor and was then discreetly distributed into targeted organizations.... 2/

        1 reply 163 retweets 594 likes
        Show this thread
      3. Kim Zetter‏Verified account @KimZetter Dec 13

        "This attack was discovered as part of an ongoing investigation" 3/pic.twitter.com/Iq8FxPpnNH

        5 replies 158 retweets 601 likes
        Show this thread
      4. Kim Zetter‏Verified account @KimZetter Dec 13

        "we do not know how the backdoor code made it into the library..research indicates...the attackers might have compromised internal build or distribution systems of SolarWinds, embedding backdoor..into a legitimate SolarWinds library" - SolarWinds.Orion.Core.BusinessLayer.dll 4/

        10 replies 164 retweets 570 likes
        Show this thread
      5. Kim Zetter‏Verified account @KimZetter Dec 13

        pic.twitter.com/i4mO7qSzT9

        1 reply 63 retweets 285 likes
        Show this thread
      6. Kim Zetter‏Verified account @KimZetter Dec 13

        pic.twitter.com/5Ujo1d1mfr

        2 replies 50 retweets 255 likes
        Show this thread
      7. Kim Zetter‏Verified account @KimZetter Dec 13

        "While updating the SolarWinds application, the embedded backdoor code loads before the legitimate code runs. Organizations are misled into believing that no malicious activity has occurred and that the program or application dependent on the libraries is behaving as expected."

        1 reply 98 retweets 403 likes
        Show this thread
      8. Kim Zetter‏Verified account @KimZetter Dec 13

        pic.twitter.com/P8wTrOOV5D

        1 reply 60 retweets 244 likes
        Show this thread
      9. Kim Zetter‏Verified account @KimZetter Dec 13

        "The malicious DLL calls out to a remote network infrastructure using the domains http://avsvmcloud.com . to prepare possible second-stage payloads, move laterally in the organization, and compromise or exfiltrate data"

        6 replies 98 retweets 377 likes
        Show this thread
      10. Kim Zetter‏Verified account @KimZetter Dec 13

        Oh, and it looks like Microsoft released a patch for the SolarWinds hack yesterday, which it is calling "Solorigate." "Microsoft detects the main implant and its other components as Solorigate." https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Solorigate.C!dha&ThreatID=2147771132 …

        8 replies 133 retweets 482 likes
        Show this thread
      11. Kim Zetter‏Verified account @KimZetter Dec 13

        I didn't get all of the DLL hashes into my previous excerpt so here are the rest of them. I'm sorry these are just images, making it impossible to copy/paste. But you can get the report from Microsoft for this info and more.pic.twitter.com/EDzPG77X8p

        8 replies 50 retweets 253 likes
        Show this thread
      12. Kim Zetter‏Verified account @KimZetter Dec 13

        Apologies for calling the Windows Defender update a patch. To clarify, Microsoft did not release a patch for the SolarWinds vuln, they released an update to their definitions to detect the malicious SolarWinds DLL.

        4 replies 61 retweets 292 likes
        Show this thread
      13. Kim Zetter‏Verified account @KimZetter Dec 13

        Here is FireEye's report on the SolarWind hack, published today. They're calling the threat SUNBURST:https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html …

        6 replies 123 retweets 331 likes
        Show this thread
      14. Kim Zetter‏Verified account @KimZetter Dec 13

        SolarWinds: "We are recommending you upgrade to Orion Platform version 2020.2.1 HF 1 as soon as possible..The latest version is available in the...Customer Portal..An additional hotfix release, 2020.2.1 HF 2 is anticipated to be made available Tues Dec 15" https://www.solarwinds.com/securityadvisory …

        3 replies 105 retweets 286 likes
        Show this thread
      15. Kim Zetter‏Verified account @KimZetter Dec 13

        This is from FireEye: "After an initial dormant period of up to two weeks, it retrieves and executes commands, called 'Jobs', that include the ability to transfer files, execute files, profile the system, reboot the machine, and disable system services...

        2 replies 41 retweets 174 likes
        Show this thread
      16. Kim Zetter‏Verified account @KimZetter Dec 13

        "The malware masquerades its network traffic as the Orion Improvement Program (OIP) protocol and stores reconnaissance results within legitimate plugin configuration files allowing it to blend in with legitimate SolarWinds activity...

        1 reply 35 retweets 177 likes
        Show this thread
      17. Kim Zetter‏Verified account @KimZetter Dec 13

        "The backdoor uses multiple obfuscated blocklists to identify forensic and anti-virus tools running as processes, services, and drivers....Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website"

        2 replies 37 retweets 166 likes
        Show this thread
      18. Kim Zetter‏Verified account @KimZetter Dec 13

        pic.twitter.com/qjbbuTMVBB

        2 replies 15 retweets 110 likes
        Show this thread
      19. Kim Zetter‏Verified account @KimZetter Dec 13

        "The victims have included government, consulting, technology, telecom and extractive entities in North America, Europe, Asia and the Middle East. We anticipate there are additional victims in other countries and verticals."

        2 replies 59 retweets 184 likes
        Show this thread
      20. Kim Zetter‏Verified account @KimZetter Dec 13

        .@CISAgov has issued an emergency directive on actions that gov agencies need to take immediately to mitigate against the SolarWinds threat: https://cyber.dhs.gov/ed/21-01/ pic.twitter.com/pKdCGr1OK5

        2 replies 77 retweets 195 likes
        Show this thread
      21. Kim Zetter‏Verified account @KimZetter Dec 13

        More from the @CISAgov emergency directive for gov agencies re SolarWinds threatpic.twitter.com/4uHukt7Hs9

        8 replies 50 retweets 150 likes
        Show this thread
      22. End of conversation

    Loading seems to be taking a while.

    Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

      Promoted Tweet

      false

      • © 2020 Twitter
      • About
      • Help Center
      • Terms
      • Privacy policy
      • Cookies
      • Ads info