The United States, United Kingdom, and Poland publicly attributed the SolarWinds Orion supply-chain compromise to Russia’s SVR intelligence service, describing it as part of a broader campaign of malicious cyber activity. The White House announced measures to impose costs on the Russian government, while the UK said a low single-digit number of its public-sector organizations were targeted and Poland warned that the fallout extended beyond the United States into Europe, aligning its response with NATO and EU statements. The campaign stemmed from trojanized Orion updates distributed in 2020 that deployed the Sunburst backdoor to fewer than 18,000 customers, with a smaller subset selected for follow-on exploitation.
Subsequent disclosures showed the intrusion reached deep into U.S. government and enterprise cloud environments. The U.S. Department of Justice said attackers accessed Microsoft 365 email accounts at 27 U.S. Attorneys’ offices, including severe exposure in multiple New York districts, while reports also identified breaches at NASA and the FAA. Technical analysis found the operators abused Azure AD, OAuth application permissions, and Microsoft Graph API access to impersonate trusted applications, escalate privileges, and exfiltrate email and tenant data. Industrial organizations were also exposed: Kaspersky estimated that 32.4% of attributable domains tied to the malware belonged to industrial entities, with more than 20 such organizations found running backdoored Orion software across several countries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
The Department of Justice disclosed that the SVR breached Microsoft Office 365 email accounts belonging to employees at 27 U.S. Attorneys' offices, with especially severe impact in four New York districts.
The European Union published a declaration of solidarity with the United States on April 15, 2021, after Washington attributed the SolarWinds campaign to Russia and imposed sanctions. The declaration referenced concern over malicious cyber activities affecting ICT products and services, but stopped short of explicitly condemning the SolarWinds operation or announcing EU sanctions.
Poland issued a statement expressing concern over U.S. information that the Russian Federation conducted cyberattacks using SolarWinds Orion and said European countries were also affected.
The United States and United Kingdom publicly attributed the SolarWinds compromise to Russia, with the UK naming the SVR and the White House tying the espionage activity to the Russian government.
Microsoft published and open-sourced CodeQL queries on 2021-02-25 to help organizations hunt for code-level indicators associated with the Solorigate/SUNBURST campaign. In the same disclosure, Microsoft said its internal investigation found some account activity and source-code viewing but no evidence of source-code modification, build-environment compromise, malicious binary changes, or production-environment tampering.
Check Point Research published analysis of the post-compromise cloud phase, describing abuse of Azure AD applications, Microsoft Graph permissions, and OAuth tokens for lateral movement and data exfiltration.
Kaspersky ICS CERT reported that more than 20 industrial-sector organizations had backdoored SolarWinds software installed, based on telemetry and decoded domain analysis.
The DOJ had previously confirmed on January 6, 2021, that the SolarWinds threat actor breached the department's Microsoft O365 email environment.
The Department of Justice said the actor's access to compromised Office 365 accounts lasted until approximately December 27, 2020.
Microsoft published an Azure Active Directory workbook to help organizations assess exposure and investigate risk related to the Solorigate/SolarWinds compromise. The release provided defenders with a cloud-focused assessment tool during the response to the campaign.
Microsoft published guidance on understanding Solorigate identity indicators of compromise for Azure Active Directory environments, providing defenders with identity-focused detection and investigation details for the campaign.
FireEye, Microsoft, and SolarWinds announced discovery of the large SolarWinds Orion supply-chain attack on December 13, 2020.
The U.S. Department of Justice said the threat actor began accessing compromised Microsoft 365 email accounts at U.S. Attorneys' offices on approximately May 7, 2020.
Microsoft said the attackers deployed a backdoor through Orion's update mechanism on compromised networks in late March 2020.
Trojanized SolarWinds Orion builds were released between March 2020 and June 2020, distributing the Sunburst backdoor to victims through the software update mechanism.
Microsoft's timeline said the attackers trojanized the SolarWinds Orion IT monitoring platform in February 2020, laying the groundwork for the supply-chain compromise.
A Washington Post report, confirmed by U.S. officials, identified NASA and the FAA as compromised in the SolarWinds espionage campaign, bringing the number of publicly identified breached federal agencies to nine.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
techcommunity.microsoft.com
Open sourcebleepingcomputer.com
Open sourcecfr.org
Open sourcegov.pl
Open sourcetechcommunity.microsoft.com
Open sourcetechcommunity.microsoft.com
Open sourcebloomberg.com
Open sourcewhitehouse.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.