cloud.google.com SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability
Article Content
- •SUNBURST backdoor exploits trojanized SolarWinds updates, affecting global organizations.
- •Malware remains dormant for up to two weeks before executing commands and blending in with legitimate traffic.
- •The campaign is attributed to APT29, a sophisticated state-sponsored actor.
The SUNBURST backdoor, discovered by FireEye, exploits trojanized updates to SolarWinds Orion software, affecting numerous public and private organizations globally. The attack vector involves a malicious DLL, SolarWinds.Orion.Core.BusinessLayer.dll, which communicates with Command and Control (C2) servers while mimicking legitimate SolarWinds traffic. Initial access was gained through compromised updates from March to May 2020, with the malware remaining dormant for up to two weeks before executing commands. Victims include government, consulting, technology, and telecom sectors across North America, Europe, Asia, and the Middle East. The campaign is attributed to the state-sponsored group APT29, previously known as UNC2452, and has been ongoing since its discovery. FireEye continues to monitor the situation and has notified affected entities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Apt29, Cobalt Strike and SolarWinds in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Knight Office Phishing Kit Targets Microsoft 365 Accounts via Session Hijacking A new phishing kit named 'Knight Office' has been identified, targeting Microsoft 365 accounts by stealing active login sessions instead of passwords. Discovered by Huntress during an investigation of suspicious sign-in activity in August 2026, the kit uses a sophisticated dashboard to manage victims and harvested…