The SolarWinds intrusion was carried out through trojanized Orion software updates that delivered the SUNBURST backdoor to a wide range of victims, including U.S. government agencies and private-sector organizations. FireEye’s disclosure that its own network had been breached helped expose the broader campaign, which investigators and U.S. officials widely linked to Russian state espionage, with the SVR cited as the most likely actor. Reported victims included the Departments of State, Treasury, Commerce, Energy, Homeland Security, and the National Institutes of Health, and responders warned that eradication and recovery would take months.
Technical analysis showed SUNBURST was engineered for stealth: it could delay execution for up to 14 days, avoid test and lab environments, check for security tools and researcher systems, and even modify Windows service registry settings to weaken some protections after reboot. The malware used domain generation and HTTP(S) command-and-control, then exfiltrated data with encrypted POST requests—sending large payloads as compressed, XOR-obfuscated application/octet-stream data and hiding smaller payloads inside fake JSON structures with Base64 chunks. In response, defenders published threat-hunting resources, indicators of compromise, Splunk and SQL queries, and tools that emulate SUNBURST’s blacklist logic to identify processes, services, and drivers that would cause the malware to terminate.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Microsoft published technical analysis of additional Nobelium malware families—GOLDMAX, GOLDFINDER, and SIBOT—expanding public understanding of the post-SolarWinds toolset and tradecraft used by the operators.
Microsoft published its Solorigate resource center, consolidating guidance, research, and updates related to the SolarWinds-linked campaign later tracked as Nobelium. The page was updated on March 4, 2021, reflecting Microsoft's ongoing public response and defender support efforts.
NPR reported that multiple U.S. agencies, including State, Treasury, Commerce, Energy, Homeland Security, and NIH, were affected, and that U.S. officials such as Mike Pompeo viewed Russia's SVR as the most likely actor.
A visible commit labeled "Correction" was made to Sophos's SolarWinds threat-hunting repository, reflecting continued maintenance of its defensive guidance and IOC resources.
Cado Security published a de-obfuscated OrionImprovementBusinessLayer.cs source file for the SUNBURST backdoor, exposing its delayed activation, victim fingerprinting, DNS-to-HTTP command-and-control flow, and extensive remote tasking capabilities. The code also revealed anti-analysis checks, service and registry manipulation logic, and embedded infrastructure references including avsvmcloud.com and appsync-api.
Sophos published the "solarwinds-threathunt" GitHub repository with collated IOCs, SQL queries, and Splunk searches to help defenders identify vulnerable SolarWinds servers and hunt for compromise.
FireEye announced on December 8 that it had been breached and that some of its offensive security tools were stolen, helping expose the broader SolarWinds espionage campaign.
According to FireEye's Kevin Mandia, the attackers deployed actual malicious code in SolarWinds Orion updates from March through June 2020, establishing the SUNBURST supply-chain compromise.
Kevin Mandia said the attackers inserted an innocuous code addition into the SolarWinds supply chain in October 2019 to validate their access and technique before deploying the full malicious capability.
A technical analysis detailed how the trojanized SolarWinds.Orion.Core.BusinessLayer.dll was loaded by SolarWinds.BusinessLayerHost.exe, described SUNBURST's victim-ID generation and avsvmcloud.com C2 hostname scheme, and published associated file hashes and domains. The write-up also documented dormancy, single-instance enforcement, AD-domain checks, and repeated blacklist checks for security tools, services, and drivers.
Symantec published technical analysis of how SUNBURST sends data back to operators using HTTP(S) POST requests, including large-payload XOR-encrypted blobs and smaller payloads hidden in fake JSON structures.
SentinelLabs published SolarWinds_Countermeasures, a tool that replicates SUNBURST's process, service, and driver blacklist logic to show whether the malware would exit on a given system.
Symantec published analysis showing SUNBURST delayed execution, checked for lab environments and security tools, and attempted to disable some security products through Windows service registry changes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
notes.netbytesec.com
Open sourceaka.ms
Open sourcesymantec-enterprise-blogs.security.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceen.wikipedia.org
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.