Skip to content
SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability

SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability

First seen 16 Jun 2026, 11:49 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 11:40 UTC
  • SUNBURST backdoor exploits trojanized SolarWinds updates, affecting global organizations.
  • Malware remains dormant for up to two weeks before executing commands and blending in with legitimate traffic.
  • The campaign is attributed to APT29, a sophisticated state-sponsored actor.

The SUNBURST backdoor, discovered by FireEye, exploits trojanized updates to SolarWinds Orion software, affecting numerous public and private organizations globally. The attack vector involves a malicious DLL, SolarWinds.Orion.Core.BusinessLayer.dll, which communicates with Command and Control (C2) servers while mimicking legitimate SolarWinds traffic. Initial access was gained through compromised updates from March to May 2020, with the malware remaining dormant for up to two weeks before executing commands. Victims include government, consulting, technology, and telecom sectors across North America, Europe, Asia, and the Middle East. The campaign is attributed to the state-sponsored group APT29, previously known as UNC2452, and has been ongoing since its discovery. FireEye continues to monitor the situation and has notified affected entities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 95d ago How this analysis works

Timeline

2020-03-01
Trojanized updates released
Malicious updates containing the SUNBURST backdoor were posted to the SolarWinds updates website, affecting users.
cloud.google.com
2020-05-01
Final trojanized update released
The last of the trojanized updates was posted, further expanding the attack surface for the SUNBURST backdoor.
cloud.google.com
2020-12-13
Initial discovery of SUNBURST
FireEye published details on the SUNBURST backdoor, revealing its sophisticated evasion techniques and operational security.
cloud.google.com
2022-05-01
APT29 attribution confirmed
FireEye merged UNC2452 with APT29, confirming the state-sponsored nature of the SUNBURST campaign.
cloud.google.com
2026-06-16
Ongoing monitoring and updates
FireEye continues to monitor the SUNBURST campaign and has notified affected organizations of their exposure.
cloud.google.com

More articles in this cluster (2)

Following this threat?

Track Apt29, Cobalt Strike and SolarWinds in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed