SUPERNOVA is a .NET web shell and backdoor associated with compromises of SolarWinds Orion servers during the broader period of investigation into the SolarWinds incidents in 2020–2021. It masquerades as a legitimate SolarWinds web service handler or DLL and enables a remote operator to send, compile, and execute C# code in memory through the Orion web application, providing persistent remote access on compromised servers. Reported behavior includes inspection of HTTP requests and execution of web-shell functionality via crafted request parameters, allowing operators to run arbitrary logic without deploying conventional binaries for each task.
SUPERNOVA has been observed on Windows-based SolarWinds Orion systems and is distinct from the SUNBURST supply-chain backdoor, despite early public confusion due to temporal overlap and shared victim technology. Multiple assessments concluded SUPERNOVA should be treated as a separate intrusion path rather than evidence of the Orion software supply-chain compromise itself. In one documented intrusion, an actor first accessed a victim environment through a VPN using valid accounts, moved laterally to the Orion appliance, installed SUPERNOVA via PowerShell, likely leveraged CVE-2020-10148 to execute commands as SYSTEM through the Orion API, harvested credentials from the Orion server, dumped LSASS memory, exfiltrated staged data through the victim web server, deleted logs, and later reused stolen credentials for additional SMB and WMI-based activity. These observations show SUPERNOVA functioning as an access-enabling post-compromise implant within broader hands-on-keyboard operations.
The malware is commonly discussed alongside SolarWinds-related tooling such as SUNBURST, TEARDROP, and SUNSPOT, and some reporting has listed it within APT29-related tool inventories. However, high-confidence reporting also states SUPERNOVA was not linked to the same actor responsible for the SUNBURST supply-chain operation and appeared less sophisticated and unsigned compared with that tooling. The malware primarily targets enterprise Orion deployments, making affected organizations those operating SolarWinds network management infrastructure, including government and commercial environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA believes the logs would have likely revealed the threat actor exploited CVE-2020-10148, an authentication bypass vulnerability in SolarWinds Orion Application Programming Interface (API) that allows a remote attacker to execute API commands. CISA believes the threat actor leveraged CVE-2020-10148 to bypass the authentication to the SolarWinds appliance and then used SolarWinds Orion API ExecuteExternalProgram() to run commands with the same privileges the SolarWinds appliance was running (in this case SYSTEM). | The threat actor then moved laterally to the entity’s SolarWinds Orion appliance and established persistence by using a PowerShell script to decode and install SUPERNOVA... The SUPERNOVA webshell allows a remote operator to dynamically inject C# source code into a web portal provided via the SolarWinds software suite.
the National Security Agency released an advisory earlier this month about CVE-2020-4006, a command injection vulnerability, stating that Russian state-sponsored actors were actively exploiting the vulnerability and suggesting US Government agencies patch immediately. This vulnerability exists in five VMware software products focused on identity and access management.
Trend Micro's Zero-Day Initiative (ZDI) provided technical analysis of recently patched vulnerabilities in the SolarWinds Orion Platform. CVE-2020-14005, one of these vulnerabilities, has been linked to the recent SUNBURST cyberattack on SolarWinds. These vulnerabilities, when combined, could allow an unauthenticated attacker to execute arbitrary code as Administrator on an affected system.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
As part of the observed campaigns, malware such as BazarLoader, Cobalt Strike, MiniDuke, “CosmicDuke”, Sunburst, SUPERNOVA, and more, were employed by APT29 attackers.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
...post-exploitation activity and filewrites occur within inetpub in-the-wild and are more indicative of web-facing exploitation with artifacts more similar to CVE-2019-8917.
established Persistence by using a PowerShell script (Command and Scripting Interpreter: PowerShell [T1059.001]) to decode and install SUPERNOVA
"The parameters required for webshell remote code execution include the C# code intended to be compiled and executed by the .NET C# compiler..."
This additional malware, dubbed SuperNova, was deployed as a DLL file that allowed attackers to remotely send, compile, and execute C# code on compromised machines.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
Boot or logon initialization scripts, scheduled tasks, valid accounts, manipulating accounts, creating accounts, server software component, create/modify system process, event triggered execution, boot or logon autostart execution, hijack execution flow (MITRE ATT&CK: T1037, T1053, T1078, T1136, T1505, T1543, T1546, T1547, T1574)
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
"UNC3886 has exploited CVE-2023-34048 to enable command execution on vCenter servers..." / "VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers." / "SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148)."
Once running, it inspects and responds to HTTP requests with appropriate HTTP query strings, cookies, and HTML form values. It can also execute web shell commands via a specific HTTP request format.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... SUNSPOT, SUPERNOVA, TEARDROP, TrailBlazer...
A trojanized SolarWinds Orion .NET DLL webshell that adds a DynamicRun() method to compile and execute attacker-supplied C# in-memory via CSharpCodeProvider, enabling arbitrary .NET payload execution without writing assemblies to disk.
Mentioned only as another malware/tool used in campaigns attributed to APT29.
Malware that impersonates a legitimate SolarWinds DLL.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.