Research into two prominent intrusion cases found that severe compromises may have stemmed from comparatively simple security weaknesses rather than uniquely advanced tradecraft. In one case, analysis of leaked OilRig tooling said the group's Poison Frog/Glimpse command-and-control server trusted agent-supplied input in its Node.js upload handling, creating a directory traversal flaw that could allow arbitrary file writes. The writeup said an attacker could append code to srvr.js, crash the process, and rely on automatic restart behavior to gain remote code execution on the C2 server, potentially helping explain reports that Turla had previously hijacked OilRig infrastructure.
A separate assessment of the SolarWinds Orion breach argued that exposed credentials and accessible development information likely gave attackers a practical path into the company's update environment. The account said SolarWinds had accidentally exposed update server credentials on GitHub, after which attackers could have studied public repositories, moved laterally into developer systems, modified Orion code, and distribute trojanized, digitally signed updates from the official server between March and May 2020. Those malicious updates reportedly reached victims including DHS, FireEye, and the U.S. Treasury, while the malware used HTTP-based command-and-control, system profiling, file transfer and execution, service disruption, reboots, and Cobalt Strike deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
According to the SolarWinds writeup, attackers digitally signed and distributed trojanized Orion updates from the official SolarWinds update server between March and May 2020. The affected organizations named in the article include DHS, FireEye, and the U.S. Treasury.
The SolarWinds analysis states that update server credentials were accidentally exposed on GitHub in 2019. The writeup presents this as a plausible initial access path to the company's update infrastructure.
A researcher published an analysis describing a directory traversal flaw in OilRig's Poison Frog/Glimpse C2 server that could enable arbitrary file write and remote code execution by modifying srvr.js and forcing a restart. The article argues this weakness may help explain prior reporting that Turla had hijacked OilRig infrastructure.
A leaked source-code dump allegedly tied to OilRig in 2019 exposed the server-side Node.js code for the Poison Frog/Glimpse command-and-control infrastructure. The later analysis says this leak revealed insecure trust of agent-supplied input in file upload handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.