Volexity reported that the threat actor it tracks as Dark Halo used the compromised SolarWinds Orion platform to breach multiple organizations, including a US-based think tank, in activity overlapping with FireEye’s UNC2452 reporting. In one intrusion tied to July 2020, the actor’s apparent objective was to steal email from selected executives, policy experts, and IT staff. Investigators said the attackers relied heavily on legitimate Microsoft Exchange administration features, including ActiveSync manipulation, mailbox export requests, and exfiltration staged through Outlook Web App infrastructure, while minimizing malware use and removing evidence where possible.
Volexity also described a separate incident in which Dark Halo bypassed Duo-protected MFA for Outlook Web App after obtaining the Duo integration secret key from the compromised OWA server and forging a valid duo-sid cookie. The firm said the technique did not reflect a vulnerability in Duo’s product, but rather abuse made possible by prior server compromise. The report characterized the actor as highly sophisticated, using living-off-the-land methods, selective malware deployment, and command-and-control infrastructure overlapping with the broader SolarWinds campaign, with volatile evidence loss preventing full reconstruction of the initial access path in one case.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Volexity publicly reported that Dark Halo was tied to multiple intrusions, including the July 2020 think tank breach likely enabled by the SolarWinds compromise. The report also detailed the actor's stealthy tradecraft, selective malware use, evidence cleanup, and overlapping infrastructure with the broader SolarWinds campaign.
In a separate intrusion disclosed by Volexity, Dark Halo bypassed Duo-protected multi-factor authentication for Outlook Web App by obtaining the Duo integration secret key from the compromised OWA server and forging a valid duo-sid cookie. Volexity emphasized this was not a vulnerability in Duo itself, but a consequence of prior server compromise.
In July 2020, a threat actor tracked by Volexity as Dark Halo compromised a US-based think tank through the trojanized SolarWinds Orion platform. Volexity linked this intrusion to activity overlapping with FireEye's UNC2452 reporting.
Following the intrusion, Dark Halo focused on collecting email from selected executives, policy experts, and IT staff. The actor used Exchange administrative tools, ActiveSync manipulation, mailbox export requests, and staged exfiltration through Outlook Web App infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 68 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.