SUNSPOT is a Windows malware implant used to compromise the SolarWinds Orion software build process during the 2020 SolarWinds supply-chain intrusion. Associated with APT29, also tracked as NOBELIUM and attributed to Russia’s Foreign Intelligence Service, it inserted the SUNBURST backdoor into Orion builds that were subsequently distributed through legitimate software updates. SUNSPOT operated within the compromised build environment rather than serving as the backdoor installed on downstream customer systems.
SUNSPOT monitored running processes, identifying Microsoft MSBuild instances by hashing process names and inspecting command-line arguments to locate targeted Orion builds. It decrypted embedded SUNBURST source code from AES-128-CBC-encrypted blobs, backed up a legitimate source file, and temporarily replaced it with malicious source code for compilation. After the build completed, it restored the original source and deleted temporary backup artifacts to conceal the modification. It used native Windows APIs for process inspection and file replacement, maintained encrypted local logs, and masqueraded as a legitimate system component. A scheduled task configured by the attackers maintained its persistence at host startup.
Its immediate target was SolarWinds’ software development and build infrastructure. By compromising the integrity of Orion releases, SUNSPOT enabled downstream initial access in an espionage campaign affecting government and commercial organizations, including technology, consulting, and telecommunications sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT29 also created a scheduled task to maintain SUNSPOT persistence when the host booted during the 2020 SolarWinds intrusion.
Nobelium had managed to compromise the SolarWinds software build environment and used a custom implant called SUNSPOT to load the SUNBURST backdoor into the Orion software update.
In a blog post late last night, the infosec firm said the Orion-targeting malware, which it codenamed Sunspot, had "several safeguards" to ensure its deployment of compromised code into new Orion builds didn't trigger SolarWinds' suspicions.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
let build_processes = dynamic ( [ "MSBuild.exe" , "dontnet.exe" , "VBCSCompiler.exe" ] )
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
SUNBURST source code used generic variable names and pre-obfuscated strings, and was likely sanitized of developer comments before being added to SUNSPOT.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
APT37 leverages the Windows API calls: VirtualAlloc(), WriteProcessMemory(), and CreateRemoteThread() for process injection.
Once build is complete, replace malicious code files with legitimate code from the backups created.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
let build_processes = dynamic ( [ "MSBuild.exe" , "dontnet.exe" , "VBCSCompiler.exe" ] )
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Their toolkit includes ... SUNBURST, SUNSPOT, SUPERNOVA, TEARDROP...
A custom implant used in the SolarWinds compromise to insert the SUNBURST backdoor into Orion software builds.
Build-system malware used to insert the SUNBURST backdoor into SolarWinds Orion software builds by hijacking compilation processes and swapping in malicious source code while avoiding build failures.
Implant referenced in citation material.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.