SecPod

Learn Search

Search across all Learn content

← Back to Security Research
UNC1945 Infiltrates Corporate Networks through a Solaris Zero-Day Bug

UNC1945 Infiltrates Corporate Networks through a Solaris Zero-Day Bug

A new zero-day vulnerability  (CVE-2020-14871) in Oracle Solaris has been brought to light by the FireEye security research team, Mandiant. Moreover, the vulnerability has been reported as being actively exploited. A Vulnerability Management System can resolve these issues. Hence, the sophisticated ...

Nov 3, 2020By Nitish B3 min read

A new zero-day vulnerability  (CVE-2020-14871) in Oracle Solaris has been brought to light by the FireEye security research team, Mandiant. Moreover, the vulnerability has been reported as being actively exploited. A Vulnerability Management System can resolve these issues. Hence, the sophisticated threat actor, UNC1945, has been known to use the zero-day bug to break into corporate networks.

The vulnerability, tracked as CVE-2020-14871, affects the Pluggable Authentication Module (PAM) component of the Solaris Operating Systems. However, the hacker group leveraged this bug and installed a backdoor called SLAPSTICK. This backdoor enables the collection of credentials and connection details that assist further compromise. Another key tool used by UNC1945 is an “Oracle Solaris SSHD Remote Root Exploit” that goes by the name EVILSUN. This tool was a zero-day exploit and was purportedly available on a black-market website. The hacker group also used a backdoor called LEMONSTICK that facilitates command execution, the establishment of tunnel connections, and file operations. Vulnerability management tools can prevent these attacks.

The threat actor reportedly deployed SLAPSTICK and LEMONSTICK on a Solaris 9 Server to gain elevated privileges and persistence. They then used SSH Port Forwarding in order to reach the internal networks via the Internet.

UNC1945:

UNC1945 set up custom QEMU Virtual Machines on several hosts, starting with a ‘start. sh’ script. The script consisted of TCP forwarding settings and SSH tunnels to give direct access to UNC1945 and obscure this from the target network. Each VM observed to be running a ‘Tiny Core Linux OS’ that comes with pre-loaded tools. The tools consisted of the likes of Mimikatz, Powersploit, Responder, Procdump, CrackMapExec, PoshC2, Medusa, JBoss Vulnerability Scanner, etc.

UNC1945 used utilities like LOGBLEACH and STEELCORGI to clean the logs and hinder investigations.

Using tools like Mimikatz and the credentials captured through SLAPSTICK, the hacker group could traverse and gain access to various target network sections. HP-UX and Linux systems compromised with brute force over SSH. Backdoors like TINYSHELL and OKSOLO employed on the systems after privilege escalation. On Windows environments, UNC1945 used IMPACKET with SMBEXEC to remote execution of commands. In some breaches, UNC1945 uses a SPARC executable a reconnaissance tool, which referred to as Luckscan or BlueKeep. BlueKeep is a security bug in Microsoft’s RDP and could result in remote code execution.

Impact of CVE-2020-14871

The vulnerability could lead to remote exploitation without authentication and could result in the takeover of corporate networks.

Affected Solaris Versions

Solaris 10Solaris 11

Solution for CVE-2020-14871

Oracle has issued a patch to CVE-2020-14871 in its latest advisory. Mandiant urges the customers affected by this vulnerability to update their operating systems with the latest patch.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

UNC1945 Infiltrates Corporate Networks through a Solaris Zero-Day Bug | SecPod