SolarWinds disclosed that the SUNBURST compromise of its Orion platform led to actual follow-on intrusions at fewer than 100 customers, despite roughly 18,000 organizations downloading tainted updates. Investigators said the attackers, widely attributed by the U.S. government to Russia’s SVR and tracked as NOBELIUM/UNC2452/Dark Halo, inserted a backdoor into signed Orion updates and used delayed activation, DNS-based victim profiling, and selective second-stage deployment to focus on high-value targets. Victims included U.S. government agencies and private-sector organizations, while related activity also reached Mimecast, where the same actor accessed encrypted customer service account credentials and compromised certain authentication certificates affecting a small number of Microsoft 365 tenants.
Incident response findings showed the campaign extended well beyond the initial Orion malware, with attackers stealing email, moving laterally through on-premises networks, bypassing MFA in some cases, forging SAML tokens, and abusing Azure AD and Microsoft 365 to access cloud resources. Research from Volexity, Symantec, Microsoft, and others detailed command-and-control through avsvmcloud[.]com, HTTP-based second-stage operations, mailbox theft, and stealthy use of legitimate identity infrastructure. In response, CISA issued an emergency directive, released the CHIRP detection tool, and published eviction guidance warning that full remediation may require rebuilding identity systems, rotating credentials, and isolating affected networks to remove long-term adversary access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
CISA issued detailed eviction guidance on May 21, 2021 for organizations affected by the SolarWinds and Active Directory/M365 compromise, covering pre-eviction, eviction, and post-eviction steps.
CISA announced CHIRP on April 15, 2021 as a forensic collection and scanning tool to detect SolarWinds-related indicators of compromise and post-compromise activity in on-premises Windows environments.
The U.S. government formally attributed the broader SolarWinds-related activity to Russia's Foreign Intelligence Service, the SVR.
Mimecast confirmed that the same actor behind the SolarWinds compromise was responsible for Mimecast's previously disclosed breach and said encrypted customer service account credentials in the U.S. and U.K. were accessed and potentially exfiltrated.
Symantec released technical analysis of SUNBURST's DNS and HTTP command-and-control process, including how DNS A records encoded commands and CNAMEs enabled secondary C2.
Microsoft said on January 14, 2021 that it would track the actor behind the SolarWinds campaign as NOBELIUM, replacing its earlier primary designation Solorigate.
On December 14, 2020, Volexity released additional research and indicators on SolarWinds-related compromises, including details of a Duo MFA bypass and email theft at a U.S. think tank.
NPR reported that SolarWinds worked with DHS to issue a public statement about the incident on December 13, 2020.
CISA issued an emergency directive on December 13, 2020 to mitigate the compromise of SolarWinds Orion network management products.
Volexity said FireEye published a blog on December 13, 2020 describing a compromise of SolarWinds involving a backdoor distributed via an Orion software update and tracking the actor as UNC2452.
Netresec said passive DNS data showed Palo Alto Networks had installed the malicious SUNBURST backdoor and entered STAGE2 on September 29, 2020; the company's CEO later confirmed it was affected.
Netresec's passive DNS analysis tied corp.qualys.com to STAGE2 SUNBURST beacons on July 22 and 23, 2020, indicating the victim was advanced for follow-on activity.
In July 2020, Volexity identified suspicious administrative commands and ActiveSync anomalies in the think tank's Exchange environment and confirmed targeted email export and exfiltration via OWA.
Volexity observed the SolarWinds server making DGA-style DNS queries under avsvmcloud.com and receiving CNAME responses to freescanonline.com between June 30 and July 16, 2020.
Volexity said a third intrusion at a U.S.-based think tank occurred via SolarWinds Orion in June and July 2020, tying the victim activity to the broader campaign.
SolarWinds said the actual supply-chain attack began in March 2020. NPR reported tainted Orion updates were distributed between March and June 2020.
According to CrowdStrike as cited by NPR, the attackers returned in February 2020 with an implant that inserted a backdoor during the SolarWinds software build process.
SolarWinds disclosed that the attackers performed a test run in October 2019 to confirm they could deploy malicious code into Orion builds.
SolarWinds said the threat actor conducted a test run to validate its ability to deploy malicious code into the Orion application. NPR also cited CrowdStrike saying an early proof-of-concept related to modifying signed SolarWinds software dated to September 12, 2019.
In an SEC filing, SolarWinds said fewer than 100 customers were actually hacked through SUNBURST, clarifying that about 18,000 customers downloaded a tainted Orion update but only a small selected set were activated as targets.
NPR reported that the Biden administration responded to the SolarWinds operation with sanctions on Russia and considered additional executive-order measures on software security and federal cyber practices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
lawfareblog.com
Open sourceus-cert.cisa.gov
Open sourcetherecord.media
Open sourcenpr.org
Open sourceblog.truesec.com
Open sourcevolexity.com
Open sourcepicussecurity.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.