Dark Halo
Dark Halo is the name Volexity uses for a state-sponsored threat actor linked to multiple intrusions in late 2019 and 2020, including activity overlapping with FireEye’s UNC2452 reporting and the SolarWinds Orion compromise. Reporting cited in the content also notes that anonymous government sources associated the group behind the hacks with APT29 / Cozy Bear, believed to be tied to Russia’s FSB, but Volexity itself is described as tracking the actor as Dark Halo. Based on the provided content, Dark Halo targeted a US-based think tank and focused primarily on stealing email from selected executives, policy experts, and IT staff. Volexity investigated three separate incidents involving this actor at one think tank. In the first, the actor used multiple tools, backdoors, and malware implants and remained undetected for several years. In the second, the actor returned after remediation by exploiting a vulnerability in the organization’s Microsoft Exchange Control Panel. In the third, Volexity concluded the likely infection vector was the compromised SolarWinds Orion platform in June and July 2020. The actor’s tradecraft included living off the land where possible, selective malware use, evidence cleanup, and repeated re-entry after apparent eviction. Observed techniques included Exchange Management Shell reconnaissance using cmdlets such as Get-ManagementRoleAssignment and Get-WebServicesVirtualDirectory; use of a renamed AdFind binary as sqlceip.exe; PowerShell and schtasks.exe for lateral movement via scheduled tasks; mailbox theft using New-MailboxExportRequest; deletion of evidence with Remove-MailboxExportRequest; and manipulation of ActiveSync access using Set-CASMailbox to add attacker-controlled device IDs. Exported PST files were compressed with 7z into password-protected archives and staged in Exchange OWA web-accessible directories for HTTP retrieval. Volexity also documented a notable MFA bypass during OWA access. After compromising the OWA server, Dark Halo obtained Duo’s integration secret key (akey) and used it to precompute a valid duo-sid cookie. With a valid username and password, this allowed the actor to access a mailbox protected by Duo MFA without triggering a second-factor challenge. The content explicitly states this was not a vulnerability in Duo, but a consequence of compromise of the integration secret on the server. Infrastructure overlap with the SolarWinds campaign was observed through shared command-and-control indicators and a backdoored SolarWinds Orion server. Domains and infrastructure mentioned in the content include avsvmcloud.com, freescanonline.com, lcomputers.com, webcodez.com, and solartrackingsystem.net. Known aliases directly mentioned in the content are UNC2452, APT29, and Cozy Bear.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Tradecraft
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
68 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromised an OWA server and bypassed Duo-protected MFA by obtaining the Duo integration secret key (akey) from the server and forging a valid duo-sid cookie after successful password authentication.
State-sponsored threat actor linked here to the supply chain attack that compromised public and private organizations. The group repeatedly penetrated a think tank, maintained long-term undetected access, and bypassed Duo MFA by stealing the Duo integration secret key (akey) from an Outlook Web App server and generating a valid duo-sid cookie.
Conducted repeated intrusions into a think tank and used privileged access on an Outlook Web App server to steal a Duo integration secret (akey), generate a valid duo-sid cookie, and bypass MFA in order to access targeted email accounts and remain undetected for extended periods.
Compromised an OWA server and bypassed Duo-protected MFA by obtaining the Duo integration secret key (akey) from the server and generating a valid duo-sid cookie, allowing access with only username and password.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.