SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability

SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability

9h ago cloud.google.com 84% similarity 75.5
Share:

Article Content

Browse articles
ThreatCluster

The SUNBURST backdoor, discovered by FireEye, exploits trojanized updates to SolarWinds Orion software, affecting numerous public and private organizations globally. The attack vector involves a malicious DLL, SolarWinds.Orion.Core.BusinessLayer.dll, which communicates with Command and Control (C2) servers while mimicking legitimate SolarWinds traffic. Initial access was gained through compromised updates from March to May 2020, with the malware remaining dormant for up to two weeks before executing commands. Victims include government, consulting, technology, and telecom sectors across North America, Europe, Asia, and the Middle East. The campaign is attributed to the state-sponsored group APT29, previously known as UNC2452, and has been ongoing since its discovery. FireEye continues to monitor the situation and has notified affected entities.

Key Points: • SUNBURST backdoor exploits trojanized SolarWinds updates, affecting global organizations. • Malware remains dormant for up to two weeks before executing commands and blending in with legitimate traffic. • The campaign is attributed to APT29, a sophisticated state-sponsored actor.

ThreatCluster AI

Timeline

2020-03-01
Trojanized updates released
Malicious updates containing the SUNBURST backdoor were posted to the SolarWinds updates website, affecting users.
cloud.google.com
2020-05-01
Final trojanized update released
The last of the trojanized updates was posted, further expanding the attack surface for the SUNBURST backdoor.
cloud.google.com
2020-12-13
Initial discovery of SUNBURST
FireEye published details on the SUNBURST backdoor, revealing its sophisticated evasion techniques and operational security.
cloud.google.com
2022-05-01
APT29 attribution confirmed
FireEye merged UNC2452 with APT29, confirming the state-sponsored nature of the SUNBURST campaign.
cloud.google.com
2026-06-16
Ongoing monitoring and updates
FireEye continues to monitor the SUNBURST campaign and has notified affected organizations of their exposure.
cloud.google.com

Community

Browse all →