SUNBURST, also known as Solorigate, is a Windows backdoor distributed through compromised SolarWinds Orion software updates during the 2020 SolarWinds supply-chain operation. It was embedded in a legitimate Orion software library and distributed with SolarWinds digital signatures. SUNSPOT inserted the malicious code into Orion builds. The operation is attributed to APT29, associated with Russia’s Foreign Intelligence Service (SVR), and affected government, consulting, technology, telecommunications, and other organizations worldwide.
SUNBURST provides remote command execution through a tasking mechanism supporting file transfer and execution, file deletion, registry modification, system profiling, rebooting, and service disabling. It collects host, operating-system, user, domain, network-configuration, process, service, and driver information. Command-and-control communications use DNS and HTTP, with traffic disguised as the Orion Improvement Program protocol. Its communications employ Base64 encoding, single-byte XOR encryption, junk data, and formatting that resembles benign XML or JSON.
The backdoor delays activity for up to approximately two weeks and checks processes, services, and drivers against obfuscated blocklists to identify security and forensic tools. It can disable security services and store reconnaissance results in legitimate plugin configuration files. Payload execution uses VBScript and Rundll32, while registry-based execution mechanisms support follow-on access. Cleanup functions remove files, proxy settings, firewall rules, and persistence-related registry entries. Operators selectively deployed additional malware to a subset of compromised organizations, including TEARDROP and subsequent Cobalt Strike implants. SUNBURST is distinct from SUPERNOVA, a separate Orion-associated webshell attributed to a different intrusion operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Trend Micro's Zero-Day Initiative (ZDI) provided technical analysis of recently patched vulnerabilities in the SolarWinds Orion Platform. CVE-2020-14005, one of these vulnerabilities, has been linked to the recent SUNBURST cyberattack on SolarWinds. These vulnerabilities, when combined, could allow an unauthenticated attacker to execute arbitrary code as Administrator on an affected system. | The attackers used the access provided by this application to plant a backdoor known as Sunburst onto affected machines.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT29 was able to get SUNBURST signed by SolarWinds code signing certificates by injecting the malware into the SolarWinds Orion software lifecycle.
“This attack code, called SUNBURST by security researchers, notified the threat actors that it had been installed each time a company performed its Orion updates.”
...18,000 of its 300,000 customers downloaded a version of its Orion software that was tainted with the Sunburst malware, the attackers activated the malware only on a handful of customers networks.
The malicious builds were later used to deliver a backdoor tracked as Sunburst to "fewer than 18,000," but, luckily, the threat actors only picked a substantially lower number of targets for second-stage exploitation.
Kaspersky also made a connection between the Russian Turla hacking group and the SolarWinds hackers after finding feature overlaps between the Sunburst backdoor and the Kazuar backdoor linked to Turla in the past.
Once installed, SUNBURST would sleep for 12-14 days before it contacted the group’s C&C domain via DNS.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
1,938 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in the SolarWinds compromise, featuring DNS-based command-and-control beaconing and DGA-style subdomain activity discussed here through log analysis and detection gaps.
Backdoor implanted into SolarWinds Orion via a compromised build pipeline and distributed through legitimate software updates as part of a supply-chain attack.
A backdoor implanted into Trojanized SolarWinds Orion software updates that beaconed to attacker-controlled C2 infrastructure, enabled remote access, and could facilitate delivery of additional malware and data exfiltration.
Backdoor malware injected into trojanized SolarWinds Orion updates and distributed through signed software updates.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.